Impact
The vulnerability is an improper neutralization of input during web page generation, leading to reflected XSS within the WPCHURCH plugin. An attacker can craft a URL or form submission that causes the plugin to echo user‑supplied data without proper encoding, allowing arbitrary JavaScript execution in the browser of any user who loads the crafted content. This can lead to session hijacking, credential theft, or defacement of the site, compromising confidentiality, integrity, and availability of user sessions.
Affected Systems
Dasinfomedia WPCHURCH plugin versions up to and including 2.7.0 are affected. Administrators should verify their plugin version and ensure it is not within this vulnerable range.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity, while an EPSS score of less than 1% suggests exploitation activity is expected to be low. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw remotely by sending a crafted request that includes the untrusted input processed by the plugin; the bug requires the affected parameter to appear in a page rendered to a user.
OpenCVE Enrichment