Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw caused by improper neutralization of user input during web page generation. Attackers can inject crafted data that results in arbitrary JavaScript executing in the victim’s browser. This can lead to session hijacking, defacement, or phishing attacks targeted at site visitors.
Affected Systems
The flaw affects the WordPress List Related Attachments plugin developed by Baden, specifically all releases from the earliest version up to and including 2.1.6.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability is of moderate severity. The EPSS score of less than 1 % indicates a low probability of live exploitation at present, and the entry is not listed in CISA’s KEV catalog. The likely attack vector is a user navigating to a page where the plugin displays unescaped input, enabling signature‑based or DOM‑based payload delivery.
OpenCVE Enrichment
EUVD