Impact
The WordPress Image Wall plugin version 3.0 and earlier suffers from a reflected XSS flaw that occurs when the plugin processes user‑supplied input without proper escaping.
Affected Systems
This vulnerability affects the Parakoos Image Wall plugin for WordPress, impacting all installations using version 3.0 or earlier. The product is listed as Image Wall by Parakoos. No specific sub‑versions are singled out beyond the <=3.0 upper bound.
Risk and Exploitability
The CVSS v3.1 base score is 7.1, indicating a high risk of exploitation. The EPSS score of less than 1% suggests a low current probability, and the vulnerability is not in the CISA KEV catalog. Because the flaw is reflected XSS, an attacker can embed malicious scripts in query strings or form inputs that are rendered on the image‑wall page, typically requiring only a victim to click a crafted link or open a modified page. Once executed, the attacker could steal session cookies, deface the site or redirect users to malicious domains.
OpenCVE Enrichment
EUVD