Impact
The Passwordless WP plugin fails to properly neutralize user input during web page generation, resulting in a reflected XSS vulnerability. This flaw permits an attacker to inject and execute arbitrary JavaScript within the context of a victim’s browser, potentially leading to session hijacking, defacement, or credential theft. The primary weakness is identified as CWE‑79, reflecting improper handling of user‑supplied data during output rendering.
Affected Systems
WP Busters: Passwordless WP – Login with your glance or fingerprint plugin, versions from the initial release up to and including 1.1.6.
Risk and Exploitability
With a CVSS score of 7.1 and an EPSS below 1%, the likelihood of widespread exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. The attack would be carried out by an adversary crafting a malicious link or form that triggers the reflected XSS when a victim visits the site. The flaw is client‑side and requires user interaction, but the impact on confidentiality, integrity, or availability is significant if the injected script succeeds.
OpenCVE Enrichment
EUVD