Impact
The flaw is an improper neutralization of input that leads to reflected XSS. The CVE states that the vulnerability is present in Random Quotes versions up through 1.3. Based on the description, it is inferred that an attacker can craft a URL or input that includes malicious JavaScript, which the plugin will echo unfiltered into the generated page. Such injection can impact confidentiality, integrity, and availability by allowing the attacker to steal user data, hijack sessions, deface the site, or execute malicious actions within the victim’s browser.
Affected Systems
The affected product is the WordPress plugin Random Quotes developed by srcoley, affecting all installations using version 1.3 or earlier. The plugin is commonly embedded in WordPress sites that display random quotes or sayings, potentially exposed to any site visitor.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% shows a low probability of widespread exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker can exploit it by sending a crafted request directly to the plugin’s endpoint without needing authentication, making it readily reproducible from any open web page that hosts the plugin.
OpenCVE Enrichment
EUVD