Impact
The Lexicata plugin for WordPress contains an improper neutralization of input during web page generation flaw that allows reflected cross‑site scripting. An attacker can craft a URL or form input that is reflected in the browser without proper encoding, enabling the execution of arbitrary JavaScript in the context of a victim’s session. This can be used to steal authentication cookies, deface the site, or redirect users to malicious resources.
Affected Systems
Vendors: Lexicata. Product: Lexicata WordPress plugin. Affected versions include all releases up to and including 1.0.16; versions prior to the first released update are also impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score of less than 1% suggests the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the most likely attack vector is a remote attacker manipulating a publicly accessible web request that the plugin processes, resulting in the reflected script executing in a victim’s browser.
OpenCVE Enrichment
EUVD