Impact
The WP_DEBUG Toggle plugin for WordPress contains a reflected cross‑site scripting flaw due to improper neutralization of user input when rendering the page. When a malicious payload is included in a request that reaches the plugin’s output, the payload is reflected back to the victim’s browser and executed, resulting in arbitrary client‑side script execution.
Affected Systems
All WordPress installations that have the plugins.club WP_DEBUG Toggle plugin installed at version 1.1 or earlier are affected. This includes every release up to and including 1.1.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity vulnerability, while the EPSS score of <1% shows a very low likelihood of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a crafted URL that a victim visits; this inference suggests that no authentication is required. Because the flaw only impacts client‑side execution, it does not provide direct server compromise.
OpenCVE Enrichment
EUVD