Impact
In the Podamibe Nepal Podamibe Twilio Private Call plugin for WordPress, an improper neutralization of input during web page generation results in a Reflected XSS vulnerability. The flaw allows attackers to embed malicious scripts in crafted URLs or form inputs that are echoed back to the user’s browser without proper sanitization, potentially enabling attacks such as session hijacking, cookie theft, defacement, or phishing.
Affected Systems
The vulnerability affects the Podamibe Twilio Private Call plugin distributed by Podamibe Nepal for WordPress versions up to and including 1.0.1. No other versions are listed as impacted.
Risk and Exploitability
With a CVSS base score of 7.1, the issue is classified as High severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation at present, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers would need to entice a user to click a malicious link or submit a specially crafted input that is reflected back, suggesting a directed or social‑engineering attack vector. Despite the low exploitation probability, the potential client‑side compromise warrants immediate attention.
OpenCVE Enrichment
EUVD