Impact
The Trackserver plugin for WordPress contains an improper neutralization of input during page generation that results in a DOM‑based cross‑site scripting vulnerability. An attacker can inject malicious scripts that execute in the victim’s browser, enabling session hijacking, defacement, or phishing attacks (inferred). This flaw undermines the integrity and confidentiality of the user’s session state, and can be leveraged to target any visitor who loads the affected page (inferred).
Affected Systems
All installations of the tinuzz Trackserver plugin for WordPress up to and including version 5.1.0 are vulnerable. The vulnerability applies to all WordPress sites that have not upgraded beyond this version threshold.
Risk and Exploitability
The CVSS score of 6.5 categorises this as a moderate‑to‑high severity issue, though the EPSS score of less than 1% indicates a very low current exploitation probability. Because it is DOM‑based XSS, exploitation typically requires the attacker to send a crafted request or otherwise influence user‑controlled input that is reflected in page rendering (inferred). The lack of an official CISA KEV listing further suggests limited exploitation activity at present (inferred).
OpenCVE Enrichment
EUVD