Impact
The vulnerability exists in versions of the Wireless Butler WordPress plugin up to and including 1.0.11 and allows attackers to inject arbitrary JavaScript into web pages rendered by the plugin. This flaw, identified as Improper Neutralization of Input During Web Page Generation, can enable attackers to execute code in the context of a victim’s browser, potentially leading to credential theft, session hijacking or defacement of the site.
Affected Systems
All installations of the Wireless Butler plugin for WordPress that are at version 1.0.11 or earlier are affected. No specific PHP version dependencies are listed, so any WordPress environment hosting the legacy plugin can be compromised.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level, and the EPSS score of less than 1 % suggests a low probability of active exploitation at the moment. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely exploit this flaw by crafting a malicious link containing the payload and luring users to click it, resulting in client‑side code execution. Because the flaw is reflected, it does not require authentication or privileged access.
OpenCVE Enrichment
EUVD