Impact
The az-content-finder plugin contains an improper neutralization of user-supplied input that results in a reflected XSS vulnerability. The flaw allows attackers to inject and execute arbitrary JavaScript within a victim’s browser. No further effects are described in the CVE summary. Based on the description, the likely attack vector involves a specially crafted GET request that returns the injected payload in the rendered page.
Affected Systems
Vulnerable versions are all releases of the antonzaroutski AZ Content Finder plugin up to and including 0.1. The plugin is used within WordPress sites that have the az-content-finder active.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. EPSS is below 1%, suggesting a low probability of widespread exploitation, though it is not listed in KEV. Based on the description, attackers can exploit the flaw by crafting a special GET request containing malicious payloads that are reflected in the plugin’s response. The impact is localized to the victim’s browser session, which is inferred from typical reflected XSS behaviour.
OpenCVE Enrichment
EUVD