Impact
The ComparePress plugin contains an improper neutralization of input during web page generation, allowing reflected XSS. An attacker can embed malicious scripts in crafted URLs that the plugin does not sanitize, enabling the execution of code in the victim’s browser. This can lead to credential theft, session hijacking, defacement, or additional payload delivery, compromising confidentiality, integrity, and availability of the site for browsing users.
Affected Systems
The vulnerability affects WordPress sites running thebloghouse ComparePress plugin version 2.0.8 or earlier. No specific minor versions are listed, so all releases up to 2.0.8 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of < 1% suggests the likelihood of exploitation is low, and the vulnerability is not currently listed in CISA KEV. Attackers would typically exploit the flaw by creating malicious URLs and convincing users to click them or embedding them in social engineering content. Successful exploitation requires the victim to be browsing a site powered by the affected plugin; no privileged or server‑side code execution is provided.
OpenCVE Enrichment
EUVD