Impact
The vulnerability is an improper neutralization of input during web page generation, allowing reflected XSS. An attacker can trick users into clicking a malicious link that includes crafted input, causing arbitrary scripts to run in the victim's browser. This can lead to session hijacking, defacement, or other client‑side compromise consistent with CWE‑79.
Affected Systems
ZooEffect plugin for WordPress, versions up to and including 1.11. The affected product is known as 1pluginjquery ZooEffect, commonly distributed as the jQuery Photo Gallery Slideshow Flash plugin. The vulnerability exists in versions from an unknown earliest release up to 1.11 inclusive.
Risk and Exploitability
CVSS score of 7.1 indicates high risk. EPSS <1% suggests low probability of exploitation at present, and KEV shows it is not yet in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is a web‑based reflected XSS that requires a victim to follow a crafted URL or submit malicious input that is echoed back by the plugin. Detection is difficult because the payload is client‑side, but the impact is severe for users who enable the plugin and do not sanitize input.
OpenCVE Enrichment
EUVD