Impact
This vulnerability is an improper neutralization of input during web page generation that allows reflected XSS in the Hung Trang Si SB Breadcrumbs plugin. The flaw lets an attacker inject malicious JavaScript that is reflected back to a victim’s browser. The likely attack vector is through a crafted URL or other form of reflected input that a user follows in a browser; based on the description, it is inferred that the attacker needs to lure a victim into visiting a malicious link.
Affected Systems
WordPress sites running the Hung Trang Si SB Breadcrumbs plugin version 1.0 or earlier are affected. All releases from the initial version up to and including 1.0 contain the vulnerability.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Because the plugin is commonly installed on WordPress sites, it remains a target for attackers who can embed malicious links that trigger the reflected XSS flaw.
OpenCVE Enrichment
EUVD