Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attacker‑supplied scripts to be stored and later executed when the login redirect page is rendered. The flaw falls under CWE‑79 and can be leveraged to steal credentials, hijack sessions, or redirect users to malicious sites without their consent.
Affected Systems
The affected product is the Arefly Login Redirect WordPress plugin, versions up to and including 1.0.5. The plugin can be installed on any WordPress site, and any user who can configure the plugin’s redirect URL or related settings is a potential vector for exploitation.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves an attacker injecting malicious JavaScript into a stored input field—such as the redirect URL field—within the plugin’s configuration. Once the payload is executed in the user’s browser, the attacker can perform malicious actions that compromise confidentiality, integrity, or availability of the site.
OpenCVE Enrichment
EUVD