Impact
Improper neutralization of input in the CM Pop-Up Banners plugin allows reflected Cross‑Site Scripting. When a victim visits a crafted URL containing malicious script, the script runs in the victim’s browser, potentially enabling cookie theft, session hijacking, or other browser‑based attacks.
Affected Systems
The vulnerability exists in CreativeMindsSolutions CM Pop-Up Banners plugin for WordPress, versions up to and including 1.7.6.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. The EPSS score of less than 1% suggests the likelihood of exploitation is low at present, and the flaw is not listed in the CISA KEV catalog. A typical attack requires the user to click a malicious link or be tricked into visiting a URL that includes the vulnerable input; no special conditions such as administrative access are required.
OpenCVE Enrichment
EUVD