Impact
This vulnerability allows the injection of arbitrary JavaScript into the plugin’s output because user-supplied input is not properly neutralized during web page generation. The impact is that a victim’s browser would execute crafted scripts, which could manipulate the page or perform unwanted actions. The description does not provide details on the specific scope or the exact nature of the exploitation, so any inference about the attack path must be explicitly marked as such.
Affected Systems
The Pressaholic WordPress Video Robot – The Ultimate Video Importer plugin, versions up to and including 1.20.0, is affected. Any WordPress site that has installed this plugin is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of <1% reflects a low likelihood of exploitation today, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote and network accessible, inferred from the description that user-controlled input is reflected in page output.
OpenCVE Enrichment
EUVD