Impact
The vulnerability is an improper neutralization of user input that is reflected back to the browser, leading to a cross‑site scripting vulnerability. An attacker can craft a URL or form input that triggers the plugin to output malicious JavaScript, which can then steal session cookies, deface the site, or perform other malicious actions on behalf of a logged‑in user. The flaw exists in all releases of the Bauernregeln plugin up to and including version 1.0.1.
Affected Systems
The affected product is the WordPress Bauernregeln plugin developed by Rally Vincent. Versions from the earliest available up to 1.0.1 are impacted. Any WordPress site that has this plugin installed without the official patch is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 places this as a medium‑to‑high severity issue, while the EPSS score of < 1% indicates a currently low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit the flaw simply by supplying malicious data in a request that the plugin echoes, so a remote, unauthenticated attacker with network access to the site can trigger the attack.
OpenCVE Enrichment
EUVD