Impact
The plugin fails to escape user‑supplied input that is reflected back into the HTML response, creating a classic reflected XSS flaw. A crafted request can inject arbitrary JavaScript which will run in the context of any visitor who follows the malicious link, enabling hijacking of session cookies, defacement, or phishing attempts. The weakness is identified as CWE‑79.
Affected Systems
WordPress sites that have installed Khushwant Singh’s Coronavirus (COVID‑19) Outbreak Data Widgets plugin, version 1.1.1 or older, are affected. The vulnerability applies to all plugin versions from the first release up to and including 1.1.1. Sites using later releases or different plugins are not impacted.
Risk and Exploitability
The CVSS score of 7.1 reflects moderate‑to‑high impact when successfully exploited. The EPSS score of less than 1% indicates a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to embed malicious script in a URL or form that is then reflected to a user. The attack vector is obviously external and requires user interaction, but an attacker could form malicious links in social media, email, or stolen credentials.
OpenCVE Enrichment
EUVD