Impact
A flaw in the Flickr Photostream plugin that fails to properly neutralize user input allows an attacker to inject arbitrary scripts into a webpage. When a victim visits a specially crafted URL containing unchecked query parameters, the plugin echoes the data back without encoding, causing the browser to execute the attacker’s script. This reflected XSS can lead to data theft, cookie compromise, or defacement of the site. The vulnerability is classified as CWE‑79.
Affected Systems
WordPress websites that have any release of the Flickr Photostream plugin version 3.1.8 or earlier are affected. The plugin is provided by Miro Mannino and is widely available through the WordPress plugin repository. Site owners who have not upgraded beyond 3.1.8 are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity; the EPSS score of less than 1% suggests a low current likelihood of exploitation. The flaw can be abused without authentication by delivering a malicious link to an end‑user; no privileged access is required. Because the exploit only requires a crafted URL, any user who visits the URL will see the malicious payload in their browser. The vulnerability is not listed in the CISA KEV catalog, but it should still be treated as a priority for remediation.
OpenCVE Enrichment
EUVD