Impact
The vulnerability stems from improper neutralization of user‑supplied data when the About Author plugin renders the author box HTML. This flaw, classified as CWE‑79, lets an attacker embed malicious JavaScript that executes in the victim’s browser whenever they view the affected page.
Affected Systems
WordPress sites that use Weblizar About Author plugin version 1.6.2 or earlier are affected; the flaw exists in all releases from the earliest to 1.6.2.
Risk and Exploitability
The flaw carries a CVSS score of 7.1 and an EPSS score of less than 1 %, indicating moderate severity but a low probability of exploitation at present. Exploitation can occur remotely without authentication, and the likely attack vector is an attacker submitting a specially crafted URL or form that contains malicious script, which the plugin reflects back into the page. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD