Impact
The Clink plugin for WordPress contains a DOM‑based XSS flaw where unsanitized user input is inserted into the page. Because the vulnerability is client‑side, an attacker can cause arbitrary script execution in any visitor's browser that renders the affected page. This allows the execution of client‑side code without needing authentication or elevated privileges. The impact is restricted to the browsers of users who view the compromised site, potentially allowing malicious actions such as defacement or loading of unauthorized resources; this assessment is based solely on the description that the flaw permits DOM‑based XSS. Based on the description, it is inferred that the attacker could embed scripts that execute in users’ browsers.
Affected Systems
WordPress sites that use the Aryan Themes Clink plugin version 1.2.2 or earlier are affected. Any installation that has not been updated beyond that version is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. With an EPSS score below 1 % and no presence in the CISA KEV catalog, the probability of widespread exploitation is low, but the impact on visitor browsers is still significant. Exploitation is feasible from an unauthenticated attacker via crafted URLs or input fields, as the vulnerability is DOM‑based and requires only client‑side execution. Based on the vulnerability type, the exploit path requires only client‑side execution without additional server‑side processing.
OpenCVE Enrichment
EUVD