Impact
Improper neutralization of user input in the Custom WP Store Locator plugin allows reflected cross‑site scripting. When a request contains unsanitized data that is echoed back by the plugin, a malicious script can run in the victim’s browser, allowing arbitrary JavaScript execution within the context of any user who views the affected page.
Affected Systems
All WordPress sites that have the Custom WP Store Locator plugin from any version prior to 1.4.8, including those running 1.4.7 and earlier. The plugin is supplied by the vendor umangmetatagg.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating moderate to high severity. The EPSS score is below 1 %, signifying a low, but non‑zero probability of exploitation. It is not listed in CISA’s KEV catalog. The likely attack vector is a reflected XSS that can be triggered by an attacker crafting a URL or form payload that is processed by the vulnerable plugin. Successful exploitation would enable the attacker to execute arbitrary JavaScript in the context of any user who visits the compromised page.
OpenCVE Enrichment
EUVD