Impact
iONE360 configurator, a WordPress plugin, includes an improper neutralization of input that allows a reflected Cross‑Site Scripting (XSS) attack. The flaw permits an attacker to inject arbitrary JavaScript into a web page that is then echoed back to the user in the browser. The vulnerability is classified as CWE‑79, indicating an input validation weakness related to output encoding.
Affected Systems
The affected product is the iONE360 configurator plugin for WordPress, versions up to and including 2.0.57. Any WordPress site that has this plugin installed and is running a version 2.0.57 or earlier is vulnerable. The vendor responsible is iONE360.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level. The EPSS score of less than 1% suggests that, as of the latest data, the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely through a reflected input field or an unescaped URL parameter supplied to the plugin, which an attacker can abuse by injecting malicious script.
OpenCVE Enrichment
EUVD