Impact
The vulnerability is an improper neutralization of user input during web page generation in the KaizenCoders Automatic Ban IP WordPress plugin, which allows attackers to craft a payload that is reflected back into the page and executed in the victim’s browser. This flaw enables the execution of arbitrary client‑side code but does not directly affect server‑side logic or WordPress core functionality.
Affected Systems
WordPress sites that have installed KaizenCoders Automatic Ban IP version 1.0.7 or earlier are affected. The plugin, used to block IP addresses, contains the insecure input handling for all releases up to and including 1.0.7.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote over HTTP: any visitor to a crafted URL can trigger the reflected XSS without authentication, as the vulnerable parameter is echoed directly into the response.
OpenCVE Enrichment
EUVD