Impact
The WP Colorful Tag Cloud plugin for WordPress contains a vulnerability that allows attackers to inject malicious script into web pages through reflected user input. This flaw is a classic Cross‑Site Scripting (XSS) weakness (CWE‑79), enabling attackers to execute arbitrary JavaScript in the browsers of other users who view affected pages, potentially leading to session hijacking, defacement, or data theft.
Affected Systems
WordPress sites that have the WP Colorful Tag Cloud plugin, developed by lionelroux, installed with a version of 2.0.1 or earlier. No specific version details are provided beyond the maximum affected version of 2.0.1.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for this reflected XSS flaw. The EPSS score of less than 1% suggests a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker can influence a URL or parameter that the plugin uses to render content; the outcome is limited to the user's browser context without needing elevated privileges.
OpenCVE Enrichment
EUVD