Impact
The Pootle button plugin contains an improper neutralization of user input that results in reflected cross‑site scripting. The likely attack vector is the delivery of a crafted URL that includes malicious script code, which, when visited by a user, causes that code to execute in the user's browser. This can lead to credential theft, session hijacking, or defacement of the site. The vulnerability is a classic CWE‑79 flaw and does not require authentication; it is limited to the front‑end of WordPress sites that use the plugin.
Affected Systems
WordPress sites running the Pootle button plugin from any version up to and including 1.2.0 are affected. The vendor is pootlepress, and any site that has installed the plugin in these versions should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity, while the EPSS score of less than 1% indicates that, at present, the likelihood of real‑world exploitation is very low. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited active exploitation. Attackers would typically exploit the flaw by presenting a crafted HTTP request or link that contains the malicious payload and causing an end‑user to visit it. No privileged access or additional credentials are required, and the impact is confined to the victim’s browser environment.
OpenCVE Enrichment
EUVD