Impact
An improper neutralization of input during web page generation in the Lock Your Updates plugin allows attackers to embed malicious scripts in the plugin's output, creating a reflected Cross-Site Scripting vulnerability.
Affected Systems
The vulnerability affects the WordPress plugin Lock Your Updates, developed by Rachel Cherry, for all released versions up to and including 1.1.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity, while an EPSS score of less than 1% suggests low but non-zero exploitation likelihood; the vulnerability is not listed in CISA's KEV catalog. Attackers can leverage this flaw by constructing URLs that trigger the plugin's output step, which then reflects user‑supplied data without proper encoding. A successful exploitation can execute arbitrary scripts in the context of site visitors or administrators, enabling session hijacking, defacement, or theft of credentials.
OpenCVE Enrichment
EUVD