Impact
The vulnerability is an improper neutralization of user‑supplied input during web page generation, enabling reflected cross‑site scripting. This flaw allows an attacker to inject malicious scripts that are reflected back to the browser, compromising the integrity of the web page. The weakness is classified as CWE‑79, and the CVSS score of 7.1 indicates a high severity for this remote input flaw.
Affected Systems
The DustinsCarberry MediaView plugin for WordPress is affected. Any release from an unspecified early version up to and including 1.1.2 satisfies the vulnerability criteria; versions 1.1.3 and later are not vulnerable.
Risk and Exploitability
The CVSS score of 7.1 combined with an EPSS score of less than 1% suggests that the flaw is severe but has a very low probability of exploitation in the wild. Because the plugin operates via a web interface, the likely attack vector is remote over the Internet. The vulnerability is not listed in the CISA KEV catalog, indicating that no active exploits are currently documented.
OpenCVE Enrichment
EUVD