Impact
The vulnerability arises from improper neutralization of input when the WordPress Health and Server Condition plugin generates a web page. As a result, an attacker can inject malicious script into data that the plugin reflects back to browsers. This reflected XSS can lead to unauthorized execution of arbitrary script in a victim’s browser, potentially allowing cookie theft, session hijacking, or malicious content injection. The weakness falls under CWE‑79: Improper Neutralization of Input During Web Page Generation.
Affected Systems
The issue affects the WordPress Health and Server Condition – Integrated with Google Page Speed plugin for WordPress, from the earliest releases through version 4.1.1. Users running any of those plugin versions on their WordPress sites are therefore susceptible if the plugin is active and exposed to user input.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity. The EPSS score is less than 1 %, showing that active exploitation is currently very low, though it does not rule out future attacks. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted URL or form input that the plugin reflects back to the page, allowing an attacker to deliver malicious script via the victim’s browser. No known network‑level prerequisites are required; an attacker only needs to persuade a user to visit the manipulated link or submit the malicious input.
OpenCVE Enrichment
EUVD