Impact
The vulnerability is an improper neutralization of input that allows an attacker to inject malicious script into a webpage rendered by the Digital Zoom Studio DZS Video Gallery plugin. This reflected XSS can execute arbitrary client‑side code in the context of a victim’s browser, enabling theft of session cookies, credential hijacking, or defacement of content. The weakness is classified as CWE‑79.
Affected Systems
Digital Zoom Studio’s DZS Video Gallery plugin for WordPress is affected, specifically all releases from the earliest known version up to and including 12.25. No later versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 7.1 places the flaw in the high‑severity bracket, and the EPSS score of less than 1 percent indicates it is currently unlikely to be exploited widely. The vulnerability is not catalogued in CISA KEV. Attackers are likely to exploit the flaw by inserting malicious payloads into URLs or form fields that the plugin processes without proper sanitization. Although the low EPSS suggests limited current exploitation activity, the potential impact on confidentiality and integrity of users renders the risk significant for sites that have the plugin installed.
OpenCVE Enrichment