Impact
The affected plugin contains an improper input neutralization in its page rendering routine, allowing an attacker to inject malicious script that will execute in the browser of any user who views the compromised page. This can lead to theft of session cookies, credential hijacking, or defacement of user experience, affecting the confidentiality and integrity of the site’s data. The weakness is identified as CWE‑79.
Affected Systems
WordPress users running the Credova Financial Credova_Financial plugin version 2.4.8 or earlier are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that the likelihood of public exploitation remains low at this time. The plugin does not require authentication to trigger the reflected XSS, which means any visitor to the vulnerable endpoint can be affected if they are tricked into opening a malicious link. The vulnerability is not listed in the CISA KEV catalog, so no known active exploits have been reported yet.
OpenCVE Enrichment
EUVD