Impact
The Twispay Credit Card Payments WordPress plugin contains an improper neutralization of input during web page generation that allows reflected cross‑site scripting (XSS). An attacker can embed malicious JavaScript in a URL or form field that is echoed back to the browser without proper encoding. When a victim visits the crafted link or submits the data, the browser executes the script in the context of the site, enabling session hijacking, defacement, or script injection. This weakness is classified as CWE‑79.
Affected Systems
The vulnerability impacts the Twispay Credit Card Payments plugin for WordPress with any version up through and including 2.1.2. No specific sub‑versions are listed, so any installation of the plugin at 2.1.2 or earlier is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The vulnerability is not catalogued in the CISA KEV list. The likely attack vector is via a crafted URL or form input that the plugin reflects in a generated page. Once an attacker successfully navigates a victim to the malicious page, the XSS payload runs in the victim’s browser, compromising confidentiality and integrity of the session. No additional prerequisites beyond user interaction are required, making the attack relatively straightforward if the vulnerability is present.
OpenCVE Enrichment
EUVD