Impact
The vulnerability is an improper neutralization of input during web page generation that allows malicious script code to be injected and reflected in pages rendered by the DsgnWrks Twitter Importer plugin. This flaw enables an attacker to insert script payloads that will execute in the browsers of users who view pages generated by the plugin. The CVE description does not specify further exploitation outcomes beyond code execution in the victim's browser.
Affected Systems
The plugin, developed by Justin Sternberg and named DsgnWrks Twitter Importer, is vulnerable in all releases from its initial version through 1.1.4. The flaw occurs in WordPress sites where the plugin is activated and the affected endpoint processes user input that is reflected in the page output.
Risk and Exploitability
The CVSS score is 7.1, indicating a high level of severity, while the EPSS score of less than 1% implies that exploitation is currently unlikely. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS scenario where an attacker crafts a URL or input that is processed by the plugin and reflected in the generated page, leading to script execution in the victim’s browser.
OpenCVE Enrichment
EUVD