Impact
The vulnerability occurs due to improper neutralization of input during web page generation, allowing an attacker to inject malicious scripts that are reflected back to the user. This can lead to session hijacking, credential theft, or defacement of the site. The weakness belongs to the input validation class, CWE‑79.
Affected Systems
The flaw affects the Verowa Connect plugin for WordPress released by Picture‑Planet GmbH. All installed copies with version numbers n/a through 3.0.4 are vulnerable. Administrators should review the versions deployed in their sites.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is below 1%, implying low exploitation probability according to current data. It is not part of the CISA KEV catalog. The likely attack vector is user interaction with a malicious URL or form that includes the forged script, which is then rendered by the victim’s browser.
OpenCVE Enrichment
EUVD