Impact
Improper neutralization of input during web page generation leads to a reflected XSS flaw. When a user supplies crafted data in a URL or form field, the plugin outputs that data without proper escaping, allowing arbitrary JavaScript to run in the context of the victim’s browser. The vulnerability is rooted in CWE‑79 and can enable attackers to steal session cookies, deface content, or redirect users to malicious sites.
Affected Systems
The Videowhisper MicroPayments paid‑membership WordPress plugin is affected from all versions prior to and including 3.2.4.
Risk and Exploitability
The CVSS score of 7.1 places this issue in the high‑severity range, while the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet. Attackers can exploit the flaw by crafting a URL or form input that includes malicious script content, which the plugin reflects back to the user's browser, potentially leading to session hijacking or reputational damage.
OpenCVE Enrichment
EUVD