Impact
The plugin contains an improper neutralization of input that allows reflected XSS. A malicious actor can embed JavaScript that the victim’s browser will execute, enabling session hijacking, credential theft, or arbitrary code execution in the victim’s context. The flaw falls under CWE‑79 and can compromise confidentiality and integrity of the user session.
Affected Systems
EverPress BruteGuard – Brute Force Login Protection, versions from the earliest release up to and including 0.1.4, are vulnerable. Any WordPress site that installed these releases and has the plugin activated is exposed.
Risk and Exploitability
The CVSS base score of 7.1 indicates a moderate to high impact, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at this time and the vulnerability is not yet listed in CISA KEV. Exploitation requires a victim to load a URL containing the malicious payload; no credentials or privileged access are needed, making the vector likely web‑browser‑based and user‑driven. Because the flaw is reflected, an attacker can craft a link that, when clicked by an unsuspecting user, injects the payload and carries out the attack.
OpenCVE Enrichment
EUVD