Impact
The vulnerability is an improper neutralization of input during web page generation that allows reflected cross‑site scripting. An attacker can craft a URL or form input containing JavaScript and trick a victim into visiting or submitting it, causing the browser to execute the script in the context of the WordPress site. This can lead to theft of session cookies, defacement of the site, or execution of arbitrary actions on behalf of the victim. The weakness is a classic XSS flaw (CWE‑79).
Affected Systems
The issue affects the SKT Donation plugin for WordPress, developed by sonalsinha21. Versions from the first release through 1.9 are vulnerable. No other product or version information is available beyond that limiter.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact for the above use case, while the EPSS score of <1% signals that it is unlikely to be widely exploited yet. It is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a victim clicking a malicious link or submitting crafted input via a public page; no authentication is required, so the vulnerability is exploitable by anyone with access to the vulnerable page. As a reflected XSS, the impact is confined to the victim and the particular WordPress instance affected.
OpenCVE Enrichment
EUVD