Impact
The Smart Notification plugin, versions up to 10.3, contains an input‑validation flaw that permits reflected cross‑site scripting. This weakness allows an attacker to inject JavaScript that runs in the context of the victim’s browser, potentially stealing user data, hijacking sessions, or defacing the user’s view. The vulnerability is classified under CWE‑79, reflecting improper neutralization of input during web page generation.
Affected Systems
All installations of Smart Notification version 10.3 or earlier running on WordPress sites are affected. The vendor, smartiolabs, identifies the issue in the plugin as "Smart Notification" from unspecified initial release through 10.3.
Risk and Exploitability
The CVSS base score of 7.1 denotes a high impact with moderate exploitability. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the current market. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation. Likely attack vectors involve crafting a URL containing malicious query parameters that the plugin reflects without sanitization, enabling unauthenticated attackers to deliver malicious scripts to users who click the link or visit the page.
OpenCVE Enrichment
EUVD