Impact
The ApplicantPro plugin contains an improper neutralization of input during web page generation, which permits reflected cross‑site scripting. This flaw means that user‑supplied data can be echoed back to the browser without sanitization, enabling an attacker to inject and execute arbitrary JavaScript in the victim’s browser.
Affected Systems
This vulnerability affects all installations of the WordPress Sourcing Team ApplicantPro plugin with a version number of 1.3.9 or earlier; no further sub‑range is specified.
Risk and Exploitability
The CVSS score of 7.1 indicates that the flaw is high impact. The EPSS score of less than 1% indicates a low historical exploitation probability, and it is not listed in the CISA KEV catalog. The attack vector is inferred to be a crafted request containing malicious user input that the plugin reflects back; authentication is not required, and a victim must follow a link or submit a form. Despite the low EPSS, the capacity for arbitrary client‑side code execution warrants prompt action.
OpenCVE Enrichment
EUVD