Impact
The vulnerability is a reflected cross‑site scripting flaw that allows an attacker to inject malicious scripts into the output generated by the WordPress XTRA Settings plugin. By submitting a specially crafted request or a malicious link, the plugin may return unescaped user input in an HTML context, causing the client’s browser to execute arbitrary JavaScript. This could result in theft of session cookies, hijacking of user sessions, defacement of the site, or execution of client‑side code that the attacker controls.
Affected Systems
The flaw resides in the XTRA Settings plugin for WordPress, released by fures. All installations running version 2.1.8 or earlier are affected; newer versions (2.1.9 and later) have been patched and are not covered by this issue.
Risk and Exploitability
The CVSS base score of 7.1 indicates high severity, but the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability has not been reported in the CISA KEV catalog. Exploitation would typically involve an attacker enticing a victim to click a maliciously crafted URL that triggers the reflected script on the client’s browser.
OpenCVE Enrichment
EUVD