Impact
The vulnerability is an improper neutralization of input during web page generation, allowing reflected cross‑site scripting (XSS) via malicious query parameters. Attackers can inject JavaScript that executes in the victim's browser, potentially stealing session data, hijacking accounts, or defacing the website. This weakness is identified by CWE‑79.
Affected Systems
The flaw is present in the tosend.it PAFacile WordPress plugin, affecting all releases up to and including version 2.6.1. No higher version is listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity, while the EPSS score of less than 1% suggests a low exploitation probability. Based on the description, it is inferred that the attack vector is remote, as any web user can access the plugin’s input handling. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD