Impact
The vulnerability is a DOM‑Based Cross‑Site Scripting flaw in the RaminMT:Links/Problem Reporter WordPress plugin. Improper neutralization of input during page generation lets an attacker inject arbitrary client‑side scripts that execute in the victim’s browser. This can lead to session hijacking, credential theft, defacement of content or redirection to malicious sites, affecting the confidentiality and integrity of user data.
Affected Systems
WordPress plugin RaminMT:Links/Problem Reporter, all released versions up to and including 2.6.0.
Risk and Exploitability
The CVSS score of 6.5 categorizes the flaw as medium severity, while an EPSS score of under 1% indicates a very low current exploitation probability. The plugin is not listed in CISA’s KEV catalog. Exploitation requires the attacker to craft an input path or malicious link that reaches a browser running the vulnerable plugin; any user who views the affected page would be susceptible.
OpenCVE Enrichment
EUVD