Impact
Improper neutralization of user input in the AR For WordPress plugin allows a DOM‑based cross‑site scripting flaw that can cause malicious JavaScript to run in the victim's browser. This can lead to credential theft, session hijacking, defacement or other client‑side attacks. The flaw exists because the plugin does not encode or sanitize input before rendering it in the page.
Affected Systems
The vulnerability affects the WordPress AR For WordPress plugin released by webandprint. All installations of the plugin with a version number of 7.7 or lower are impacted. Sites that use this plugin on any WordPress environment may be susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score of less than 1% means that overall exploitation probability is very low, and the flaw is not listed in the CISA KEV catalog. The attack vector is likely inbound through crafted input that a user can trigger in their browser, requiring only victim interaction with a page that uses the plugin. No server‑side code execution or credentials are required to exploit the flaw.
OpenCVE Enrichment
EUVD