Impact
The vulnerability is an improper neutralization of input during web page generation, which allows reflected cross‑site scripting (XSS). A malicious user can craft JavaScript that is returned by the plugin and executed in the victim’s browser. The flaw is triggered by user‑controlled input that is reflected in the page output.
Affected Systems
The WordPress plugin Random Posts, Mp3 Player + ShareButton from vendor dvs11, version 1.4.1 and all earlier releases are affected. Any WordPress site that has installed the plugin at or below this version is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high risk, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is user‑controlled input on the plugin’s front‑end that is reflected directly into the page without proper sanitization. Successful exploitation would allow an attacker to inject and execute arbitrary scripts in the victim’s browser.
OpenCVE Enrichment
EUVD