Impact
Improper neutralization of user input in the WordPress XML for Avito plugin leads to reflected cross‑site scripting. The vulnerable code renders unsafe input directly into the page. When a specially crafted request reaches the plugin, the malicious code is injected and executed in the victim’s browser. Based on the description, it is inferred that the attacker could potentially use this execution to steal session cookies, deface the site, or deliver other malicious payloads to users who view the affected page.
Affected Systems
The vulnerability affects the WordPress plugin XML for Avito, sold by vendor icopydoc. Any installation with version 2.5.2 or earlier is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk flaw. The EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not present in CISA KEV. Based on the description, the likely attack vector is remote exploitation through a crafted request, such as a malicious URL, which does not require additional user interaction beyond visiting the link.
OpenCVE Enrichment
EUVD