Impact
The Fancybox Plus plugin for WordPress contains an Improper Neutralization of Input During Web Page Generation flaw that can be triggered by user‑supplied data. When the plugin displays the reflected payload in the rendered page, a malicious script can execute in the browser of anyone who views the affected page, compromising confidentiality and potentially allowing data theft or session hijacking. This weakness is classified as CWE‑79.
Affected Systems
The vulnerability affects the puzich Fancybox Plus plugin for WordPress versions up to and including 1.0.1. No other vendors or product variants are listed in the CNA data.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that the exploitation rate is currently low. The flaw is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL or form submission that the plugin processes without proper sanitization, leading to reflected script execution if a user interacts with the resulting page.
OpenCVE Enrichment
EUVD