Impact
The vulnerability allows an attacker to inject arbitrary JavaScript into a victim’s browser through reflected inputs in the Realtyna Provisioning plugin. Improper neutralization of user‑supplied data (CWE‑79) means any untrusted value can appear in page output without encoding, enabling client‑side script execution.
Affected Systems
WordPress sites that include the Realtyna Provisioning plugin version 1.2.2 or earlier are affected. No other plugins or product versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a high‑severity flaw. The EPSS score of < 1% indicates a low probability of exploitation at present, and it is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL or form input that a user opens or submits, triggering the reflected XSS. Successful exploitation allows an attacker to run arbitrary JavaScript in the victim’s browser, which could lead to session hijacking, defacement, or phishing depending on the victim’s privileges.
OpenCVE Enrichment
EUVD