Impact
The Custom Widget Creator plugin contains an improper neutralization of input during web page generation that permits reflected cross‑site scripting. A request crafted by an attacker can include JavaScript code that is reflected by the plugin and executed in the browser of any user who visits the affected page, potentially allowing the attacker to run arbitrary scripts in the victim’s context.
Affected Systems
All installations of the Custom Widget Creator plugin from devbunchuk with a version number up to and including 1.0.5 are vulnerable. Any site running the plugin at those versions is at risk until the plugin is updated.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity. An EPSS score of less than 1% indicates that exploitation is currently uncommon and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, requiring a crafted URL or form submission that contains the malicious payload, and the effect is limited to the browser session of the victim. Without further information, it is possible to assume that the vulnerability is accessed via a typical web request and that successful exploitation requires the victim to load the manipulated content in a browser that does not enforce stricter CSP or XSS protection.
OpenCVE Enrichment
EUVD