Impact
The Vice Versa WordPress plugin allows attackers to inject malicious scripts via reflected input in the web page rendering process. This improper neutralization can lead to user‑agent execution of arbitrary scripts, compromising confidentiality, integrity, and availability of website content.
Affected Systems
WordPress sites running Hugh Mungus Vice Versa plugin version 2.2.3 or earlier are vulnerable. The issue applies to all installations using those pre‑2.2.4 releases regardless of other plugins or themes.
Risk and Exploitability
The configurable CVSS score of 7.1 indicates a high impact. The EPSS score is less than 1%, suggesting a low prevalence of imminent exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this weakness by manipulating reflected request parameters that the plugin includes unfiltered in generated HTML, typically via crafted URLs or search bar entries. A successful exploit would enable the execution of injected scripts in the context of the victim’s browser.
OpenCVE Enrichment
EUVD