Impact
Improper neutralization of user input during page generation in the ZD Scribd iPaper WordPress plugin allows reflected XSS that can be used by an attacker to inject malicious scripts into a page viewed by users, potentially facilitating session hijacking or the execution of arbitrary code in the victim’s browser. The weakness is categorized as CWE‑79, illustrating a lack of proper sanitization before echoing input.
Affected Systems
The ZD Scribd iPaper plugin, developed by Proloy Chakroborty, is affected in all releases up to and including version 1.0. The plugin is distributed for WordPress sites and is installed as a standard WordPress plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability, while the EPSS score of less than 1 % suggests that large‑scale exploitation is currently unlikely and no U.S. Department of Homeland Security KEV listing is present. The likely attack vector is a crafted HTTP request that includes malicious input; the payload is reflected in the response page, which can be tricked into executing in a victim’s browser. The plugin’s public nature and the absence of any defensive hardening increase the exploitability for attackers who can persuade users to visit a malicious link.
OpenCVE Enrichment