Impact
The Fusion plugin (versions 1.6.4 and earlier) contains an improper neutralization of input during web page generation that enables DOM‑based cross‑site scripting. This flaw allows malicious code to be injected into generated pages when an attacker supplies crafted input that is not properly escaped. An attacker who can cause the vulnerable plugin to render user input can potentially execute arbitrary JavaScript within the victim’s browser, leading to session hijacking, defacement, or theft of sensitive data.
Affected Systems
The vulnerability affects Agency Dominion Inc.’s Fusion plugin for WordPress, impacting all installations running any version up to and including 1.6.4.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as medium‑severity. The EPSS score of less than 1%% indicates a low probability of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote—an attacker can exploit the vulnerability by submitting malicious input via a web form, specially crafted URL, or other user‑controlled data that the plugin echoes without proper sanitization.
OpenCVE Enrichment
EUVD