Impact
Improper neutralization of user input in the ThriveDesk plugin results in a reflected XSS flaw. When an attacker supplies specially crafted query parameters, the input is rendered unescaped back into the page, allowing the attacker to execute arbitrary JavaScript in the victim’s browser. This can lead to cookie theft, session hijacking, defacement, or the execution of further malicious actions within the context of the site (CWE‑79).
Affected Systems
ThriveDesk WordPress plugin, any version up through 2.0.6, is affected. No other versions are impacted according to the vendor’s description. The plugin is used on WordPress sites that have the ThriveDesk add‑on installed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk, yet the EPSS score of less than 1% suggests that exploitation is currently rare. The flaw is not listed in the CISA KEV catalog. The attack vector is typical for a reflected XSS: a crafted URL or form input that reflects user data back to the browser. An attacker must lure a user to visit the malicious link or submit the input; no privilege escalation or server‑side compromise is required.
OpenCVE Enrichment
EUVD