Impact
The vulnerability is an improper neutralization of input during web page generation that allows reflected cross‑site scripting in the Memberpress WordPress plugin. As a result, a malicious actor could inject arbitrary client‑side scripts that run in the browser of any user who visits a crafted URL within the plugin. This can lead to session hijacking, credential theft, defacement, or the execution of additional malicious payloads. The weakness can be mapped to CWE‑79.
Affected Systems
The affectation is limited to the Memberpress plugin from any version prior to 1.12.0, distributed by Caseproof, LLC, used on WordPress sites. Administrators should verify whether the plugin is deployed on their site and if the version in use predates 1.12.0.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high risk, while the EPSS score of less than 1% suggests that exploitation probability is currently very low. The vulnerability is not listed in the CISA KEV. The likely attack vector is a crafted URL that accepts unneutralized input, implying that the exploit can be performed via a remote web request. Given these metrics, the risk remains significant for sites that have not yet upgraded the plugin.
OpenCVE Enrichment
EUVD