Impact
The vulnerability is an improper neutralization of user input when generating a blog page, resulting in a reflected XSS flaw. An attacker can deliver arbitrary JavaScript to a visitor by crafting a URL that embeds malicious code, potentially allowing cookie theft, phishing, or defacement of the site.
Affected Systems
The affected component is the WordPress plugin Flexible Blogtitle released by thaikolja. Versions from the original release up to and including 0.1 are impacted. The issue does not affect any versions above 0.1 because the input sanitization logic has been fixed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1 % suggests a relatively low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to visit a crafted URL, meaning the attack vector is a web‑based one that relies on user interaction. Once the malicious script runs, the attacker can execute any client‑side code permitted by the victim’s browser, compromising confidentiality and integrity of the site and potentially the user’s session.
OpenCVE Enrichment
EUVD