Impact
The Simple Vertical Timeline plugin suffers from an improper neutralization of input during web page generation, allowing attackers to inject script code into web pages rendered by the plugin. This DOM‑based XSS could enable attackers to run arbitrary JavaScript in the context of a victim's browser, potentially leading to session hijacking, credential theft, or defacement of the site.
Affected Systems
The vulnerability impacts the Simple Vertical Timeline plugin from Odyno, affecting all released versions up to and including 0.1. Users should verify the plugin version and ensure it is updated beyond 0.1.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would most likely exploit the flaw by tricking a user into visiting a page that includes the vulnerable plugin, injecting script via unsanitized input fields. The impact is confined to the client side, but can still compromise sensitive data or degrade user experience.
OpenCVE Enrichment
EUVD