Impact
The Omnify omnify‑widget plugin for WordPress contains an improper neutralization of user input that permits reflected X‑ss. An attacker can inject a malicious script that is executed in the browser of any visitor who loads a crafted URL or form, enabling session hijacking, defacement or covert data exfiltration. This flaw is classified as CWE‑79.
Affected Systems
The vulnerability affects the Omnify, Inc. Omnify widget plugin for WordPress, versions from the earliest release through 2.0.3 inclusive. Administrators should check the installed plugin version and note that any installation using 2.0.3 or earlier is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact if exploited, but the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The flaw is not currently listed in the CISA KEV catalog, and no public exploits have been reported. The likely attack vector is a reflected X‑ss through a crafted request to a page served by the plugin.
OpenCVE Enrichment
EUVD