Impact
Improper neutralization of input during web page generation allows a reflected XSS flaw in the Intro Tour Tutorial DeepPresentation WordPress plugin, enabling an attacker to inject and run arbitrary JavaScript in the victim’s browser. This can lead to theft of session cookies, hijacking of user accounts and phishing or defacement attacks, without needing elevated privileges on the server.
Affected Systems
The vulnerability affects the Tomáš Groulík Intro Tour Tutorial DeepPresentation plugin (dp‑intro‑tours) for WordPress, with all releases up to and including version 6.5.2 being impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity; the EPSS score is below 1 %, suggesting a low likelihood of exploitation in the wild at present, and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is a remote attacker crafting a URL that includes malicious script payloads and directing a victim to that URL, thereby causing reflected execution of the attacker’s code in the victim’s browser.
OpenCVE Enrichment
EUVD