Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attackers to inject malicious JavaScript that is returned to the user’s browser. If exploited, an attacker can run arbitrary code in the victim’s context, enabling cookie theft, session hijacking, or defacement. The weakness is a reflected cross‑site scripting flaw, classified as CWE‑79.
Affected Systems
This flaw is found in the Video Share VOD plugin for WordPress, distributed by videowhisper. All installations running any version up to and including 2.7.9 are affected. No minimum version is specified for vulnerability; thus any deployment of the plugin before the release of 2.7.10 should consider remediation.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of <1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA KEV. An attacker would need to trick a user into visiting a crafted URL that reflects malicious input; if successful, the reflected XSS can execute arbitrary JavaScript in the user’s browser.
OpenCVE Enrichment
EUVD