Impact
The Profile Widget Ninja plugin accepts user input without proper neutralization, allowing an attacker to inject and execute arbitrary JavaScript in a victim’s browser. The CVE description identifies a DOM-based cross-site scripting vulnerability but does not specify particular exploitation outcomes.
Affected Systems
The vulnerability exists in the WordPress Profile Widget Ninja plugin produced by Pankaj Mondal and affects all released versions up to and including 4.3.
Risk and Exploitability
With a CVSS score of 6.5 the severity is moderate, and the EPSS score is below 1 %, indicating a very low but non‑zero likelihood of exploitation. The flaw is not present in the CISA KEV catalog. The provided data does not detail the specific method or prerequisites for exploitation beyond the presence of DOM-based cross‑site scripting.
OpenCVE Enrichment
EUVD