Impact
Improper neutralization of user input during page rendering in the Edem CMC MIGRATE plugin allows reflected cross‑site scripting. An attacker can embed malicious script content in a URL, which the plugin then outputs without adequate sanitization, causing the script to execute in the victim’s browser, potentially exposing client‑side data.
Affected Systems
All installations of the WordPress CMC MIGRATE plugin from its first release through version 0.0.3 are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of < 1% suggests a currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is user‑directed web traffic; an attacker must craft a URL containing malicious script payloads that the victim accesses, triggering execution in the browser.
OpenCVE Enrichment
EUVD