Impact
This vulnerability allows an attacker to inject malicious scripts that run in the browser of anyone who views a crafted page. If exploited, the attacker can steal session cookies, deface content, redirect users, or execute any other JavaScript that the affected user’s environment would otherwise trust. The weakness stems from improper input neutralization when generating web page output, a classic XSS flaw.
Affected Systems
The Atarim Visual Collaboration plugin for WordPress, issued by Vito Peleg, is affected for all releases up to and including version 4.1.0. Any WordPress installation using this plugin within that version range is vulnerable and requires attention.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑impact threat, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely exploit the flaw through a crafted URL or form submission that triggers the reflected script, requiring the victim to visit or interact with the compromised content.
OpenCVE Enrichment
EUVD