Impact
The vulnerability allows an attacker to inject malicious script that is reflected back to the victim’s browser during web page generation. This reflected cross‑site scripting can execute arbitrary JavaScript within the user’s browsing context, potentially stealing session cookies, defacing the website, or redirecting users to malicious sites. The weakness is a classic input validation flaw classified as CWE‑79.
Affected Systems
The affected module is the tubegtld .TUBE Video Curator Plugin for WordPress, versions up to and including 1.1.9. Any WordPress site running those plugin iterations is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% shows a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the flaw by visiting a crafted URL that includes a malicious script payload; the plugin fails to neutralize such input before rendering.
OpenCVE Enrichment
EUVD