Impact
The plugin contains an improper neutralization of input during web page generation that allows reflected Cross‑Site Scripting. This vulnerability can enable an attacker to inject and execute arbitrary client‑side scripts in the browsers of users who visit crafted URLs, potentially leading to session hijacking, defacement, or phishing attacks. The weakness corresponds to CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
WordPress plugin NoFollow Free, versions up to and including 1.6.3. Only the listed versions are affected; newer releases are presumed not vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact if successfully exploited. The EPSS score of less than 1% suggests that widespread exploitation is unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the vulnerability can be exploited by embedding malicious scripts in URLs that a victim is directed to, thus social engineering is the most likely attack vector.
OpenCVE Enrichment
EUVD