Impact
Improper neutralization of user input during page generation in the CountDown With Image or Video Background plugin enables attackers to inject malicious scripts that run in a victim’s browser. An attacker can craft a URL or form input that contains JavaScript, which is reflected back in the page without sanitization, potentially compromising session cookies, defacing the site, or stealing sensitive information.
Affected Systems
The vulnerability affects WordPress sites using the LambertGroup CountDown With Image or Video Background plugin version 1.5 or earlier. Any installation that has not upgraded beyond 1.5 remains susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1 % suggests a low probability of active exploitation at present. The attack vector is client‑side reflected XSS, requiring an attacker‑controlled input to be reflected in the page; no elevated privileges or server‑side compromise are necessary. Because the vulnerability is not listed in the CISA KEV catalog, widespread, automated exploitation has not been reported.
OpenCVE Enrichment