Impact
The NotFound Callback Request plugin exposes a reflected Cross‑Site Scripting vulnerability due to improper neutralization of input during page rendering. An attacker can supply malicious script payloads in query parameters that are returned unescaped in the browser, leading to execution of arbitrary JavaScript in the context of a victim’s session. While this does not provide direct server‑side code execution, it enables hijacking of session cookies, defacement, or malicious redirects.
Affected Systems
The flaw affects the Callback Request plugin from all versions prior to 1.5, specifically those through version 1.4. The plugin is distributed by the NotFound vendor and is available for WordPress sites.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, and the low EPSS score (<1%) suggests that exploitation is not frequently observed. The vulnerability is not listed in the CISA KEV catalogue, implying no widespread exploitation by known threat actors. Attackers can exploit it by crafting a URL containing the malicious payload and convincing a user to visit it; thus the vector is user‑initiated browser interaction with the vulnerable plugin.
OpenCVE Enrichment
EUVD