Impact
This vulnerability is an Improper Neutralization of Input During Web Page Generation (Cross‑Site Scripting) that allows a reflected XSS attack in the ViperBar plugin for WordPress. An attacker can inject malicious scripts into user‑controlled input that is reflected back in the plugin’s output, potentially enabling session hijacking, cookie theft, or defacement of the site. The CVSS score of 7.1 reflects a high severity of this flaw.
Affected Systems
The ViperBar plugin from viperchill is affected for all versions up to and including 2.0. Users operating WordPress sites with this plugin in that version range are at risk.
Risk and Exploitability
The EPSS score of <1% indicates a low probability of exploitation at present, and it is not listed in the CISA KEV catalog. Nevertheless, reflected XSS attacks are typically trivial to construct by crafting a malicious URL or form input that is processed by the vulnerable plugin, with no authentication required. The vulnerability relies on the plugin’s failure to properly escape user input before rendering it in a web page. In environments where site visitors interact with the plugin’s functionality, the risk of compromise or defacement remains significant.
OpenCVE Enrichment
EUVD