Impact
The vulnerability is a reflected cross‑site scripting flaw caused by improper neutralization of user input during web page rendering. An attacker can embed a malicious script in a crafted request that the plugin fails to sanitize, causing the script to execute in the victim’s browser. This enables session hijacking, credential theft, defacement, or the delivery of additional malware, affecting the confidentiality and integrity of users who visit the compromised page.
Affected Systems
WordPress sites running the 5sterrenspecialist Plugin version 1.4 or earlier are impacted. The flaw remains present in all releases through the stated maximum version.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. A likely attack vector is a crafted URL or form submission that includes malicious payloads; the attacker only needs a victim to load the page for exploitation to occur. The risk is mitigated by addressing the flaw in the plugin code.
OpenCVE Enrichment
EUVD