Impact
The vulnerability arises from improper neutralization of input during page generation, allowing reflected XSS via the Dynamic URL SEO plugin. An attacker can inject malicious scripts through URL parameters that the plugin reproduces in the output. This flaw can be abused to steal user sessions, deface the site, or deliver further malware.
Affected Systems
Affected systems include WordPress installations running the brainvireinfo Dynamic URL SEO plugin version 1.0 or earlier. The issue is present in all releases prior to 1.1, and there is no mention of a later version that eliminates the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity, and the EPSS score of less than 1% suggests a low exploit probability at this moment. The vulnerability is not yet listed in the KEV catalog. The likely attack vector involves an unauthenticated attacker sending a user a malicious URL that contains a payload; this inference is based on the nature of reflected XSS.
OpenCVE Enrichment
EUVD