Impact
The vulnerability is a reflected XSS flaw caused by inadequate input neutralization in the AWcode Toolkit plugin. An attacker can craft a malicious URL that includes script payloads; when a user browses the URL, the script is executed within the victim’s browser. This allows the attacker to steal session cookies, deface the site, or perform other client‑side attacks. The weakness falls under CWE‑79, reflecting inadequate output encoding or sanitization.
Affected Systems
The flaw exists in the AWcode Toolkit WordPress plugin for all releases up to and including version 1.0.14. Version 1.0.15 and later contain the fix. The affected product is the AWcode Toolkit plugin for WordPress.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity. The EPSS score is less than 1 %, suggesting a low exploitation probability but not negligible. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is a user‑initiated request to a crafted URL on the website where the plugin is installed.
OpenCVE Enrichment
EUVD