Impact
An improper neutralization of input during web page generation allows an attacker to inject malicious scripts into the page content, leading to reflected Cross‑Site Scripting in the victim’s browser. This flaw, identified as CWE‑79, can enable attackers to execute arbitrary client‑side code, potentially stealing session cookies, defacing the site, or redirecting users to phishing domains. The incident can compromise confidentiality, integrity, and availability of user data for any browser that renders the affected content.
Affected Systems
The vulnerability affects the Eazy Under Construction WordPress plugin developed by Rob Scott. Versions from the initial release through 1.0 are all impacted; any installation of the plugin at or below that version is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests a low probability of widespread exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector comes from a crafted URL or input that the plugin fails to sanitize, meaning the attacker can target any user who visits a malicious link or submits vulnerable data. No special conditions beyond normal web interaction appear to be required for exploitation.
OpenCVE Enrichment
EUVD