Impact
An improper neutralization of input during web page generation allows a reflected XSS vulnerability in the GrandSlambert Custom Page Extensions plugin for WordPress. This weakness can enable an attacker to inject and execute arbitrary client‑side script in the browser context of a site that uses the vulnerable plugin. The flaw is identified as CWE‑79.
Affected Systems
Custom Page Extensions, a WordPress plugin distributed by GrandSlambert, is affected in all releases up to and including version 0.6. No newer versions were listed as vulnerable, but the issue is present in every plugin version <=0.6.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity of the vulnerability, while the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack likely requires a victim to be tricked into visiting a crafted URL or submitting malicious input that the plugin echoes back, which would allow the injected script to execute. No system privilege escalation or authentication bypass is required.
OpenCVE Enrichment
EUVD