Impact
The vulnerability is a reflected Cross‑Site Scripting flaw in the WordPress plugin Support Helpdesk Ticket System Lite. The plugin does not neutralize user input before rendering it back to the browser. An attacker who can embed malicious script content in a URL or form field can cause browsers of victims to execute that script.
Affected Systems
The vulnerability affects installations of the M. Ali Saleem Support Helpdesk Ticket System Lite plugin for WordPress with versions up to and including 4.5.2. The flaw is present from the plugin's earliest released version through 4.5.2.
Risk and Exploitability
The EPSS score is reported as <1 %, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL or form input that an attacker can compel a victim to visit, inferred because the flaw is a reflected XSS. The CVSS score of 7.1 indicates moderate‑high severity, but the low EPSS indicates that this vulnerability is not a high‑risk exploitation target at present.
OpenCVE Enrichment
EUVD