Impact
The vulnerability is an improper neutralization of input during web page generation, allowing reflected cross‑site scripting. An attacker can inject malicious JavaScript that is executed in the victim’s browser when a crafted URL is viewed, potentially hijacking sessions, defacing content, or deferring further attacks. The impact remains client‑side but can be leveraged for credential theft or phishing.
Affected Systems
The issue affects the WordPress Restrict Taxonomies plugin by Antoine Guillien, specifically all releases from the earliest available through version 1.3.3. WordPress sites using any of these plugin versions are susceptible.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score of <1% indicates a low overall probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via a crafted URL that a user to whom the attacker sends the link will visit, allowing the reflected script to run in the victim’s browser. Successful exploitation requires that the victim click the malicious link or otherwise load the vulnerable page.
OpenCVE Enrichment
EUVD