Impact
The plugin MemberPress Discord Addon accepts user‑supplied input without proper neutralization. This leads to a reflected XSS flaw that can inject malicious scripts into pages rendered by the site. The vulnerability could allow an attacker to steal credentials, deface content, or redirect users to malicious sites, impacting confidentiality, integrity, and availability of the affected WordPress installation.
Affected Systems
Vendors: expresstechsoftware. Product: MemberPress Discord Addon. Affected versions are all releases up to and including 1.1.1.
Risk and Exploitability
The CVSS score of 7.1 indicates non‑trivial risk. The EPSS score of less than 1% suggests a very low probability of exploitation currently, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to supply crafted input in a URL or form field that is reflected back to the browser, so the attack typically requires a user to visit a malicious link or submit a malicious form. Once a browser processes the unsanitized payload, arbitrary JavaScript can execute in the victim’s context.
OpenCVE Enrichment
EUVD