Impact
Improper neutralization of input during web page generation allows reflected XSS attacks in the Canonical Attachments plugin. An attacker can embed malicious scripts within data that is subsequently echoed back in a generated page.
Affected Systems
The vulnerability affects Hive Digital’s Canonical Attachments WordPress plugin versions from the initial release through version 1.8. Any WordPress installation containing one of these versions is potentially exposed.
Risk and Exploitability
The CVSS score is 7.1, indicating a high severity of the issue. According to the EPSS score of < 1 %, the probability of exploitation is very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is indirect and requires that an attacker be able to submit data to the plugin’s interface via a web request; the attack is performed by instructing a victim browser to execute the injected script.
OpenCVE Enrichment
EUVD