Impact
The WP‑BusinessDirectory plugin implements input handling that does not properly neutralize user data before including it in web pages, which allows an attacker to inject arbitrary JavaScript into responses that are rendered to end users. The vulnerability is a classic reflected cross‑site scripting flaw (CWE‑79). The immediate effect of exploitation is the execution of attacker‑supplied script code within the victim’s browser session, potentially affecting the data and functionality visible to that user.
Affected Systems
The affected component is CMSJunkie’s WordPress Business Directory Plugin (WP‑BusinessDirectory). Versions from the earliest available release through 3.1.2 are vulnerable; any installation running 3.1.3 or newer is assumed to be free of this flaw.
Risk and Exploitability
The vendor lists a CVSS score of 7.1, categorizing the flaw as high severity. The EPSS score of less than 1 % indicates a low probability of active exploitation, and the vulnerability is not included in CISA’s KEV catalog. The most likely exploitation route is an attacker crafting a malicious URL or form input containing JavaScript and persuading a visitor to follow it or submit it (inferred based on typical reflected XSS attack patterns). No special authentication or privilege is required to exploit the flaw.
OpenCVE Enrichment
EUVD