Impact
Improper neutralization of user input during web page generation allows an attacker to inject JavaScript that is reflected back to the victim’s browser. The effect is client‑side code execution, enabling malicious activities such as defacement, data exfiltration, or redirects, but the CVE does not describe any compromise of the underlying server or database.
Affected Systems
The Gigaom Sphinx plugin for WordPress, from the earliest release through version 0.1, is affected. Any WordPress site with this plugin installed and active, regardless of the installation date, is potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of <1 % shows that the likelihood of exploitation is currently low. It is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL containing a malicious script that is reflected into the page when a user clicks or visits it, allowing the script to execute in the victim’s browser. This inference is based on standard XSS behavior and the description of the vulnerability as a reflected XSS bug.
OpenCVE Enrichment
EUVD