Impact
The Rebuild Permalinks plugin contains an improper neutralization of input during web page generation that allows attacker-controlled input to be reflected and executed as script in the victim’s browser. When a user accesses a crafted link, the input is included in the response without proper escaping, enabling the injection of arbitrary client‑side scripts.
Affected Systems
All releases of the Rebuild Permalinks plugin from the earliest available version through 1.6 are affected. Any WordPress site that has this plugin installed and active is at risk.
Risk and Exploitability
The CVSS score of 7.1 marks this flaw as high severity. The EPSS score of less than 1% indicates a currently low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because no authentication is required, the vulnerability can be triggered remotely via a malicious URL.
OpenCVE Enrichment
EUVD