Impact
The Zalo Live Chat plugin for WordPress contains an improper neutralization of user input that allows a reflected Cross‑Site Scripting (XSS) flaw. When an attacker supplies specially crafted data that is incorporated into the page’s HTML output without proper encoding, the malicious code executes in the browser of any user who views the affected page. This attack vector can lead to theft of session credentials, defacement of the site, or the execution of further actions on behalf of the user.
Affected Systems
Affected systems are installations of Dang Ngoc Binh’s Zalo Live Chat plugin for WordPress, specifically all versions from the earliest available releases through version 1.1.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability, yet the EPSS score of less than 1% suggests that active exploitation is currently unlikely. Because the plug‑in does not appear in the CISA KEV catalog, no known mass exploitation is recorded. The most probable attack path involves the attacker crafting a malicious URL or form input that is reflected in the plugin’s output; victims must then visit or submit data through the vulnerable interface for the payload to run.
OpenCVE Enrichment
EUVD