Impact
The vulnerability is an improper neutralization of input during web page generation that allows an attacker to inject arbitrary script into a page viewed by other users. This reflected XSS flaw could be used by a malicious actor to steal session cookies, deface the site, or inject malware, potentially compromising user confidentiality, integrity, and availability. The weakness is identified as CWE‑79.
Affected Systems
The flaw exists in the Media Downloader plugin for WordPress developed by Ederson Peka. All installations of version 0.4.7.5 or earlier are vulnerable. No specific operating system or CMS version is mentioned, so any WordPress site running the identified plugin version is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1 percent suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attack would require an attacker to persuade a user to load a crafted URL containing malicious script or to obtain a form that echoes user input without proper sanitization. Once executed, the attacker could execute arbitrary JavaScript on the victim’s browser.
OpenCVE Enrichment
EUVD