Impact
The vulnerability arises from improper neutralization of user input during web page generation in the WordPress Save & Import Image from URL plugin versions up to 0.7. When a malicious script is included in the image‑URL parameter, it is reflected back into the browser without proper escaping, allowing an attacker to execute arbitrary JavaScript in the context of any user who views the affected page. The weakness is categorized as CWE‑79.
Affected Systems
The issue affects the WordPress plugin "Save & Import Image from URL" crafted by basteln3rk, impacting all releases from the initial version through version 0.7. End‑users running any of these plugin versions on a WordPress installation are susceptible unless mitigated by a patch or removal.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, yet the EPSS score of less than 1 % suggests a very low likelihood of widespread exploitation in the near term. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL containing malicious JavaScript, with no authentication required; any user who engages with the vulnerable plugin can trigger the payload.
OpenCVE Enrichment
EUVD