Impact
The vulnerability is an improper neutralization of user input during web page generation, allowing attackers to inject malicious scripts that execute in the victim’s browser. This DOM‑based XSS enables an attacker to capture session cookies, deface content, or perform other client‑side attacks as the compromised user, exploiting the weakness defined by CWE‑79.
Affected Systems
The affected product is the WordPress WP VR plugin developed by RexTheme. All releases with version numbers up to and including 8.5.14 are vulnerable; this includes any earlier unspecified releases (n/a) that contain the legacy code paths used by the plugin.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is considered moderate severity. The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest a low probability of current exploitation. However, because the attack requires only a crafted request to the vulnerable plugin, an attacker with modest resources could still trigger the XSS if the plugin is accessible in a public site.
OpenCVE Enrichment
EUVD