Impact
This flaw is a reflected cross‑site scripting vulnerability that stems from improper neutralization of user input in the DuoGeek Email to Download plugin. When a specially crafted request is sent, the plugin echoes the supplied data back into the page without sanitization, allowing an attacker to inject arbitrary JavaScript. The injected code executes in the victim’s browser with the privileges of the site, potentially enabling credential theft, session hijacking, malicious redirects, or defacement of the page.
Affected Systems
The vulnerability affects the DuoGeek Email to Download WordPress plugin in all releases from the initial release through version 3.1.0 inclusive. Users running any of these affected versions are potentially impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity with moderate complexity, while the EPSS score of less than 1% suggests exploitation probability is low but not negligible. The flaw can be triggered remotely by an attacker who can embed a malicious URL or form input, making it accessible from the public web. Although the vulnerability is not listed in CISA’s KEV catalog, the potential impact on user data and site integrity warrants timely remediation.
OpenCVE Enrichment
EUVD