Impact
The vulnerability is a DOM‑Based Cross‑Site Scripting flaw in the Filtr8 Easy Magazine WordPress plugin. An attacker could inject malicious script that executes in the browsers of site visitors, potentially leading to session hijacking, cookie theft, and defacement. The weakness is identified as CWE‑79, reflecting improper input neutralization when rendering page content.
Affected Systems
WordPress sites using the Filtr8 Easy Magazine plugin version 2.1.13 or earlier are affected. All installations that have not upgraded past the 2.1.13 release remain vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV. An attacker would need to attract users to a page that includes the vulnerable plugin; based on the description, it is inferred that the attack vector is a client‑side exploit via crafted URLs or input fields.
OpenCVE Enrichment
EUVD