Impact
The Easy School Registration plugin for WordPress contains an improper neutralization of user input during page generation that allows attackers to inject arbitrary JavaScript through reflected cross‑site scripting. This flaw can result in the execution of malicious code in the victim’s browser, potentially exposing sensitive data, compromising sessions, or facilitating further attacks. The weakness is classified as CWE‑79 and is limited to the rendering of unescaped user‑supplied data.
Affected Systems
WordPress installations running the Easy School Registration plugin version 3.9.8 or earlier are affected. The plugin vendor is Zbynek Nedoma. No later versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector is an attacker constructing a malicious URL or embedding a payload that triggers the XSS when a user opens the affected page. No additional prerequisites beyond the vulnerable plugin are mentioned in the description.
OpenCVE Enrichment
EUVD