Impact
The vulnerability is a DOM-based cross‑site scripting flaw caused by inadequate neutralization of user input during web page generation. An attacker can inject malicious scripts that run in the victim’s browser, potentially stealing session cookies, defacing the site, or redirecting users to malicious sites.
Affected Systems
WordPress installations that use the Softaculous PageLayer plugin version 1.9.4 or earlier are affected. This includes all versions from the first release through 1.9.4.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no active widespread exploitation is documented. Attacks would most likely target the end‑user’s browser via a malicious link or injected content, requiring that the vulnerable plugin is active.
OpenCVE Enrichment
EUVD