Impact
This flaw arises from UXsniff plugin's failure to properly neutralize user‑controlled input during web page generation, allowing reflected XSS that can inject arbitrary scripts into pages viewed by unsuspecting users, potentially enabling session hijacking, credential theft, or malicious redirection. The weakness is classified as CWE‑79.
Affected Systems
The vulnerability impacts the WordPress UXsniff plugin distributed by Pei Yong Goh and applies to all releases up to and including version 1.3.3. Sites that have installed any of those versions are affected.
Risk and Exploitability
With a CVSS score of 7.1 the flaw represents medium‑to‑high severity, while an EPSS score of less than 1 % indicates a low probability of real‑world exploitation, and it is not listed in CISA’s KEV catalog. The likely attack vector involves a crafted URL or input field that triggers the plugin’s rendering logic, displaying injected script to the victim. Despite the low exploitation probability, the potential impact on confidentiality and integrity warrants immediate corrective action.
OpenCVE Enrichment
EUVD