Impact
The WP Email Delivery plugin for WordPress contains a reflected Cross‑Site Scripting flaw that occurs when user input is incorporated into a web page without proper sanitization. If an attacker can supply such input, a victim who views the crafted page may have arbitrary JavaScript executed in their browser. This client‑side compromise can lead to session hijacking, defacement, or malicious redirects.
Affected Systems
WordPress sites that have the Brewlabs WP Email Delivery plugin version 1.20.11.23 or earlier. The vulnerability targets installations where the plugin is active and processes user‑supplied input for email delivery or output.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity, and the EPSS score of < 1% indicates a very low but nonzero probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is a user interacting with a site that presents crafted input; the description does not explicitly state the vector, but it is inferred that a malicious URL or form payload could trigger the XSS. Because the flaw is client‑side, it requires the victim to visit the page, but can be activated through social engineering or phishing. The risk remains significant to any organization relying on the affected plugin.
OpenCVE Enrichment
EUVD