Impact
The Advance WP Query Search Filter plugin contains an input‑sanitization flaw that allows attackers to embed malicious scripts in page URLs. This reflected XSS can execute arbitrary code in the browser of any user who visits a crafted link, potentially enabling session hijacking, credential theft, or defacement. The weakness maps to CWE‑79: Improper Neutralization of Input.
Affected Systems
WordPress sites using TC.K Advance WP Query Search Filter plugin version 1.0.10 or earlier are vulnerable.
Risk and Exploitability
The CVSS base score is 7.1, indicating a high severity reflected XSS. However, the EPSS score is less than 1 %, suggesting a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV. Attackers would typically trigger the flaw by persuading a victim to open a specially crafted URL sent via email, social media, or other means, with the malicious payload embedded in a query string processed by the plugin.
OpenCVE Enrichment
EUVD