Impact
The vulnerability is an Improper Neutralization of Input during Web Page Generation flaw that permits DOM‑Based Cross‑Site Scripting. An attacker can inject malicious JavaScript through input handling in the WP Delete User Accounts plugin, potentially compromising the user session, defacing content, or stealing credentials. This weakness is classified as CWE‑79.
Affected Systems
WordPress plugin "WP Delete User Accounts" produced by Ren Ventura. Versions from the initial release through version 1.2.3 are affected, regardless of the site’s WordPress core version.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk; the EPSS score of less than 1 % reflects a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to provide crafted input via a URL or form field that is rendered by the plugin, and a victim’s browser would execute the injected script. The compromise is limited to the context of the affected site, but it can lead to credential theft or further malware delivery within user sessions.
OpenCVE Enrichment
EUVD