Impact
The WordPress NanoSupport plugin contains an error that fails to properly neutralize user input before rendering it on a web page, allowing an attacker to inject and execute malicious script code in the context of a victim’s browser. This vulnerability is classified as Reflected Cross‑Site Scripting.
Affected Systems
Any WordPress site that has the NanoSupport plugin from the original release up to and including version 0.6.0, published by Mayeenul Islam, is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, and the EPSS score of less than 1% suggests a low current probability of exploitation. Because the flaw is reflected XSS, it is generally obtainable only when an attacker provides a victim with a crafted link or form input that the victim subsequently visits, so user interaction is required. The vulnerability is not listed in the CISA KEV catalog, indicating that no widespread active exploitation has been observed at the time of this assessment. In the absence of a publicly released patch, the risk remains until an update is verified or mitigations are applied.
OpenCVE Enrichment
EUVD