Impact
An improper neutralization flaw in the Easy Automatic Newsletter Lite plugin lets an attacker inject a malicious script that is reflected back into the response without sanitization. If a victim is tricked into visiting a specially crafted URL, the attacker’s payload runs in the victim’s browser, enabling the typical consequences of a reflected XSS flaw (such as session hijacking or defacement). The weakness is characterized as Cross‑Site Scripting (CWE‑79).
Affected Systems
The vulnerability is present in PillarDev Easy Automatic Newsletter Lite plugin versions up to and including 3.2.0. Any WordPress installation running this plugin at or below that version is affected.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity. Its low EPSS (<1%) suggests a lower likelihood of exploitation, and the flaw is not listed in CISA KEV, so no known active exploitation campaigns are reported. The attack vector is remote, requiring a malicious link or request that includes unsanitized user input. If exploited, the impact is limited to the victim’s browser.
OpenCVE Enrichment
EUVD