Impact
Improper neutralization of user input during web page generation allows an attacker to inject JavaScript that is reflected back to the victim’s browser. This reflected cross‑site scripting (XSS) can lead to session hijacking, data theft, or defacement. The weakness is identified as CWE‑79.
Affected Systems
The vulnerability exists in the AuMenu plugin developed by atelierhyper. Versions up to and including 1.1.5 are affected. Sites running any of these versions without an update are susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of < 1% shows that exploitation likelihood is low at this time. It is not listed in CISA’s KEV catalog, and the attack vector is web‑based and requires the victim to visit a crafted URL. Because the page simply reflects untrusted input, an attacker can freely construct scripts to run in the victim’s browser.
OpenCVE Enrichment
EUVD