Impact
The vulnerability arises from improper neutralization of user input during web page generation, allowing attackers to inject arbitrary script into pages rendered by the CRM Perks plugin. This reflected XSS can execute code in the context of a victim’s browser, potentially leading to session hijacking, defacement, or credential theft. The weakness is a classic input validation flaw listed as CWE-79.
Affected Systems
The CRM Perks WordPress plugin is affected for any installation using version 1.1.5 or earlier. The issue applies to all builds through the end of 1.1.5, regardless of host configuration.
Risk and Exploitability
The CVSS score of 7.1 categorises the flaw as high severity, though the EPSS score of < 1% indicates a low likelihood of exploitation. Because the vulnerability is browser‑based and can be triggered via a crafted URL, the attack vector is remote. The flaw is not listed in the CISA KEV catalog, suggesting no confirmed active exploitation yet. However, any user who clicks a malicious link while authenticated to the affected site could be exposed.
OpenCVE Enrichment
EUVD