Impact
The vulnerability is an improper neutralization of input during web page generation that allows an attacker to inject malicious scripts into pages rendered by the Bob Hostel WordPress plugin. This reflected XSS flaw enables the execution of arbitrary JavaScript in the browsers of users who visit a crafted URL. Successful exploitation can lead to session hijacking, defacement, or the delivery of additional malware, compromising user confidentiality and data integrity.
Affected Systems
The issue affects the Bob Hostel WordPress plugin versions up to and including 1.1.5.5. Any WordPress site that has installed this plugin without updating to a newer release is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of < 1% suggests a low probability of exploitation in the wild. The vulnerability is exploitable via a reflected XSS path that requires no authentication and can be triggered simply by a user accessing a malicious link. The plugin is not listed in CISA KEV.
OpenCVE Enrichment
EUVD