Impact
The Post Timeline plugin for WordPress contains an improper neutralization of input bug that allows a reflected XSS vulnerability. When a user supplies malicious data that the plugin outputs without encoding, the attacker can force the victim’s browser to execute arbitrary JavaScript in the context of the site. This script execution can lead to theft of session cookies, credential hijacking, or execution of further attacks such as click‑jacking or phishing. The weakness is a classic input‑validation issue identified as CWE‑79.
Affected Systems
The vulnerability affects the Agile Logix Post Timeline plugin in all releases from the earliest available version up to version 2.3.9. Systems running any of those versions are potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑to‑moderate severity, while the EPSS score of less than 1% suggests that active exploitation is currently rare but possible. The vulnerability is not yet listed in the CISA KEV catalog, though that status could change if an exploit were discovered. Based on the description, it is inferred that the attack vector is remote and likely via a crafted URL or form input that the plugin reflects back to the user’s browser. Should an attacker successfully supply such input, the reflected script would run with the victim’s privileges.
OpenCVE Enrichment
EUVD