Impact
The vulnerability is an XSS flaw that allows attackers to inject malicious scripts into pages rendered by the License For Envato plugin. This flaw is caused by improper sanitization of user input before it is echoed back to the page. An attacker can cause arbitrary script execution in the browser context of any user who follows a crafted link or submits a crafted form, leading to credential theft, session hijacking, or defacement.
Affected Systems
License For Envato plugin by Ashraful Sarkar Naiem, versions up to and including 1.0.0.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, meaning no confirmed widespread exploitation. Attackers can exploit the flaw via a reflected XSS vector by persuading a victim to click a malicious link; this requires user interaction and is non‑persistent.
OpenCVE Enrichment
EUVD