Impact
This vulnerability is an improper neutralization of user input during web page generation. An attacker can supply crafted input that is reflected back into the page without proper escaping, allowing the execution of arbitrary JavaScript in the context of the affected site. The primary impact is that a user visiting the affected page could run malicious scripts that steal session cookies, deface content, or load additional malicious payloads.
Affected Systems
WordPress sites running the Movylo Marketing Automation widget plugin, versions up to and including 2.0.7.
Risk and Exploitability
The CVSS score of 7.1 rates this as medium‑high severity. The EPSS score of <1% indicates a very low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is a crafted URL or form input that an unsuspecting user clicks on or submits, leading to reflected XSS on the vulnerable page.
OpenCVE Enrichment
EUVD