Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation that allows unfiltered user input to be reflected into a web page, enabling a reflected XSS attack that can execute arbitrary JavaScript in the victim’s browser.
Affected Systems
The affected product is the WordPress Shipmozo Courier Tracking plugin, version 1.0 or earlier, distributed by webparexapp.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium-level risk. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is that attackers trigger the reflected XSS by crafting a malicious request that includes the vulnerable parameter, which is then reflected into an unescaped location on the page; successful exploitation requires the victim to visit a specially crafted URL or click a link containing malicious content.
OpenCVE Enrichment
EUVD