Impact
The Alphabetic Pagination plugin contains an improper neutralization of input during web page generation, allowing reflected XSS. An attacker can craft a URL that injects malicious script into the page viewed by a victim. This can lead to session hijacking, credential theft, or defacement of the site’s content. The weakness is categorized as CWE‑79.
Affected Systems
The vulnerability affects Fahad Mahmood’s Alphabetic Pagination plugin for WordPress. Versions from the earliest available release up through 3.2.1 are impacted. Any site that has not upgraded beyond 3.2.1 is at risk.
Risk and Exploitability
The CVSS score of 7.1 denotes a high impact on confidentiality, integrity, and availability. The EPSS score of less than 1 % indicates that, at the moment, the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via a crafted URL or input parameter that the plugin reflects in the output. A site operator should treat this as a significant risk if visitors can be exposed to malicious links.
OpenCVE Enrichment
EUVD