Impact
The vulnerability is a CWE‑79 reflected cross‑site scripting flaw caused by improper neutralization of user input during page generation. An attacker can supply crafted data that the SpatialMatch IDX plugin echoes back in the HTML response, enabling the execution of arbitrary JavaScript in the victim’s browser. This client‑side code can modify page content, steal session tokens, or perform other browser‑based attacks, but cannot bypass server‑side restrictions.
Affected Systems
The affected product is the homejunction SpatialMatch IDX WordPress plugin, specifically all releases through version 3.0.9. WordPress sites that have this plugin installed at a version less than or equal to 3.0.9 are susceptible; newer versions are presumed to have the issue resolved.
Risk and Exploitability
The CVSS score of 7.1 denotes a high severity with medium to high exploitability; the EPSS score of less than 1 % indicates that, at present, the exploitation probability is very low. The vulnerability is not listed in CISA’s KEV catalogue. Attackers would need to lure a victim to a URL or input that contains malicious payload; successful exploitation requires the victim to view the reflected data in a browser, which is typical for reflected XSS scenarios.
OpenCVE Enrichment
EUVD