Impact
WordPress Insert HTML Here plugin suffers from a reflected XSS flaw caused by insufficient input sanitization. The vulnerability allows attackers to embed malicious scripts in content that the plugin renders on the page. When a victim follows a crafted link or submits malicious input, the script executes in the victim's browser, potentially stealing session cookies, executing unauthorized actions, or defacing the site. The weakness is identified as CWE-79.
Affected Systems
All WordPress installations that use the Insert HTML Here plugin version 1.0 or earlier are vulnerable. This includes every site that has the plugin active regardless of theme or other plugins. The vulnerability spans from the earliest provided version up to and including version 1.0.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity impact, while the EPSS score of <1% suggests that exploitation is currently unlikely to be widespread. The issue is not listed in the CISA KEV catalog, implying it has no known active exploits yet. The attack vector is inferred to be a reflected request (for example, a malicious URL or form submission) that the plugin fails to neutralize. Administrators should treat this as a medium‑to‑high risk that warrants swift action.
OpenCVE Enrichment
EUVD