Impact
Terminal Africa plugin for WordPress contains an improper neutralization of user input that allows attackers to inject arbitrary JavaScript into web pages. The vulnerability is a reflected cross‑site scripting flaw that can be triggered when a victim visits a crafted URL or otherwise submits malicious input that is subsequently echoed by the server. Successful exploitation could enable an attacker to steal session cookies, deface pages, or deliver malicious payloads, compromising the confidentiality, integrity, or availability of the affected site.
Affected Systems
WordPress sites running the Terminal Africa plugin version 1.13.24 or earlier are impacted. The vulnerability is present in all earlier releases, from the software's inception through version 1.13.24.
Risk and Exploitability
The CVSS base score is 7.1, indicating a high severity. The EPSS score is less than 1 %, suggesting a very low but non‑zero likelihood of exploitation in the near term. The flaw is not listed in CISA’s KEV catalog. Attackers would need to entice a user to visit a crafted link or supply malicious input via a form, making the attack vector web‑based and likely requiring user interaction.
OpenCVE Enrichment
EUVD