Impact
The .htaccess Login block plugin contains an improper neutralization of input during web page generation vulnerability that permits attackers to inject and execute arbitrary JavaScript when a user visits certain URLs. This reflected Cross‑Site Scripting flaw is categorized under CWE‑79, enabling attackers to hijack user sessions, deface the site, or perform other client‑side attacks whenever an affected user clicks a malicious link or submits a crafted request.
Affected Systems
WordPress sites that use the Anton Aleksandrov .htaccess Login block plugin, versions 0.9a and earlier.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack scenario requires a vulnerable user to interact with a crafted URL; no authentication or elevated privileges are needed for exploitation.
OpenCVE Enrichment
EUVD