Impact
Improper neutralization of input during web page generation allows an attacker to inject arbitrary JavaScript into pages served by the Image Rotator plugin in WordPress. This reflected XSS flaw can be exploited to steal victims' cookies, hijack sessions, or deface a site. The weakness is identified as CWE-79.
Affected Systems
The vulnerability affects the appten Image Rotator WordPress plugin, versions up to and including 2.0. WordPress sites that keep this plugin installed and have not applied the latest update are potentially exposed.
Risk and Exploitability
The CVSS score of 7.1 reflects a Medium to High severity, while the EPSS score of <1% indicates a low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS facilitated by malicious query parameters or user input that reaches the plugin without proper sanitization.
OpenCVE Enrichment
EUVD