Impact
The vulnerability originates from improper neutralization of user input during web page generation, allowing an attacker to inject malicious scripts that are reflected back to the victim’s browser. This flaw results in a Cross‑Site Scripting (XSS) condition that can be exploited to steal user credentials, deface content, or track user activity. The weakness is identified as CWE‑79, a classic reflection XSS flaw.
Affected Systems
The affected product is the WPEverest User Registration and Membership plugin for WordPress, available in both free and pro editions. All released versions prior to 4.2.0 are vulnerable. The plugin is distributed under the standard WordPress plugin framework.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity rating, while the EPSS score of less than 1% suggests a currently low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to entice a victim to visit a crafted URL containing malicious payloads; the reflected XSS would then execute in the victim’s browser with the privileges of the logged‑in user.
OpenCVE Enrichment
EUVD