Impact
The vulnerability is an improper neutralization of user input that allows attackers to inject malicious scripts into the web page generated by the WordPress plugin. This reflected XSS flaw can lead to execution of arbitrary JavaScript in a victim’s browser, enabling session hijacking, defacement, or the execution of further attacks in the context of the user’s credentials.
Affected Systems
The affected software is the Mapro Collins Coming Soon Countdown WordPress plugin, versions up to and including 2.2. Any WordPress site that has this plugin installed within these version ranges is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity level, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attack vector is external and involves a crafted URL or form input that the plugin fails to sanitize, allowing an attacker to embed malicious JavaScript which is then reflected back to the user’s browser.
OpenCVE Enrichment
EUVD