Impact
The WP24 Domain Check plugin fails to neutralize user‑supplied input when rendering pages, allowing attackers to inject malicious JavaScript that executes in the victim’s browser. This reflected XSS can be used for session hijacking, defacement, or phishing. The weakness is recognized as CWE‑79.
Affected Systems
All WordPress installations using the WP24 Domain Check plugin version 1.10.14 or earlier are affected. The vulnerability applies to every instance of the plugin released through that version threshold.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high potential impact when exploited. The EPSS score is below 1%, suggesting that current exploitation attempts are rare, and it is not listed in CISA’s KEV catalog. Attackers can exploit the flaw by visiting a crafted URL that includes malicious payloads, with no authentication required. Because the attack vector is sufficiently trivial—simply sending a visitor to a special link—the risk remains significant for exposed sites, despite the low probability of widespread exploitation.
OpenCVE Enrichment
EUVD