Impact
The vulnerability is an instance of Improper Neutralization of Input During Web Page Generation that allows an attacker to inject malicious JavaScript into pages served to a user. The reflected XSS can enable arbitrary script execution in the victim’s browser session. The weakness is classified as CWE‑79.
Affected Systems
WordPress installations that use the WP‑HR Manager plugin at version 3.1.0 or older are affected. The plugin, called WP‑HR Manager: The Human Resources Plugin for WordPress, is distributed by wphrmanager and is publicly available for download. No additional operating systems or PHP versions are specifically mentioned.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity of the flaw. The EPSS score of <1% shows that the likelihood of exploitation is low at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL or form field that a user clicks or submits; the attacker must convince a victim to load the vulnerable page. Because the flaw is client‑side, no special privileges are required on the server, but human users can be impacted if they interact with the reflected content.
OpenCVE Enrichment
EUVD