Impact
The User List plugin contains an Improper Neutralization of Input during Web Page Generation vulnerability that allows reflected XSS. By supplying specially crafted input, an attacker can cause the plugin to inject arbitrary JavaScript into the page returned to the victim. This can lead to theft of session cookies, defacement, or execution of further attacks in the victim's browser. The weakness is classified as CWE‑79.
Affected Systems
All instances of the WordPress User List plugin with versions up to and including 1.5.1 are affected. No additional affected versions are listed.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high severity. The EPSS score is less than 1%, suggesting a low but non‑negligible likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through a manipulated URL or form input that the plugin processes directly in the web page, an inference based on the description of reflected XSS.
OpenCVE Enrichment
EUVD