Impact
An insufficient sanitization of user‑supplied data allows a malicious script to be reflected back in a page rendered by the WordPress Infugrator plugin. When a victim loads a specially crafted URL containing JavaScript in a parameter, the plugin outputs that payload without proper escaping, resulting in the browser executing the code under the user’s privileges.
Affected Systems
The flaw is present in Cosmin Schiopu’s Infugrator WordPress plugin versions 1.0.3 and older. WordPress sites that have installed any of these versions are vulnerable until the plugin is upgraded beyond the affected releases.
Risk and Exploitability
The CVSS v3 base score of 7.1 indicates a serious flaw with medium to high impact. The EPSS score of less than 1 % suggests that exploitation in the wild is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need to entice a user to click a crafted link or otherwise send the parameter to the vulnerable endpoint; any user who visits the malicious URL would have their browser run the injected script.
OpenCVE Enrichment
EUVD