Impact
The vulnerability is an improper neutralization of input during web page generation, allowing reflected cross‑site scripting. Attackers can inject malicious script that is reflected back to the user, potentially executing arbitrary JavaScript in the victim's browser. The weakness aligns with CWE‑79.
Affected Systems
The affected product is the Plestar Directory Listing plugin supplied by hdw player. Versions up to and including 1.0 are vulnerable; all earlier or after revisions are unaffected.
Risk and Exploitability
With a CVSS score of 7.1 this vulnerability falls into the high severity range. The EPSS score is below 1%, indicating a low probability of exploitation across the public cloud at this time. It is not currently listed in the CISA KEV catalog. The likely attack vector involves an attacker crafting a malicious URL or form input that the plugin reflects, thus exploiting the XSS surface.
OpenCVE Enrichment
EUVD