Impact
Improper neutralization of input during web page generation allows a reflected cross‑site scripting vulnerability in the Tribulant Software Snow Storm plugin. The flaw permits an attacker to inject arbitrary JavaScript into pages rendered to other users, compromising the confidentiality and integrity of their web browsing session and enabling execution of malicious code on victims’ browsers.
Affected Systems
The vulnerability affects the Snow Storm plugin for WordPress from the initial release through version 1.4.6. Any WordPress installation using the plugin in these versions is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is less than 1%, suggesting a low probability of mass exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS scenario in which an attacker supplies specially crafted input—such as a query string or form field value—that the plugin fails to sanitize and subsequently renders in the page returned to the victim. An attacker who succeeds can hijack user sessions, deface content, or spread malware.
OpenCVE Enrichment
EUVD