Impact
The flaw is an improper neutralization of input during web page generation, enabling attackers to inject arbitrary HTML or JavaScript. The consequence is reflected Cross‑Site Scripting that can execute client‑side code when a victim views a vulnerable page, potentially leading to defacement, credential theft or phishing attacks.
Affected Systems
The vulnerability affects the LeadLab by wiredminds WordPress plugin distributed by wiredmindshelp. All releases from the initial build through version 1.3 are impacted.
Risk and Exploitability
The CVSS score of 7.1 classifies this as high severity. An EPSS score of less than 1 % indicates a low probability of exploitation at this time, and the flaw is not listed in CISA’s KEV catalog. Attackers are likely able to trigger the vulnerability by sending a crafted request to the plugin’s web interface, which reflects untrusted input back to the victim’s browser.
OpenCVE Enrichment
EUVD