Impact
The WP‑Hijri plugin (version 1.5.3 and earlier) fails to neutralize user‑supplied input, allowing an attacker to inject and reflect malicious JavaScript when a victim visits a crafted URL. An exploited XSS payload could steal session cookies, deface pages, or redirect users to phishing sites, thereby compromising confidentiality and integrity of the site and its visitors.
Affected Systems
WordPress sites running the WP‑Hijri plugin up to and including version 1.5.3 are impacted. The plugin is third‑party code, not core WordPress, and the affected range is "from n/a through <= 1.5.3".
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high risk, but its EPSS score is less than 1% and it is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation at present. The attack vector is likely web‑based, where an attacker sends a malicious link to a user or embeds the payload in a page that triggers the vulnerable code. No known exploit code has been publicly released, but the nature of reflected XSS makes it trivial for an attacker to craft and test payloads once the vulnerability is known.
OpenCVE Enrichment
EUVD