Impact
The flaw is a reflected Cross‑Site Scripting vulnerability caused by improper input sanitization in the CRM Perks support‑x module. It permits an attacker to embed malicious scripts within a crafted URL that, when accessed, will be executed by the victim’s browser during page rendering. Based on the description, it is inferred that a malicious script could be injected into the page and executed in the user’s browser.
Affected Systems
The vulnerability affects installations of the WordPress CRM Perks plugin that are version 1.1.7 or earlier. All users of the support‑x module without a newer version are impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation. This CVE is not listed in the CISA KEV catalog. Exploitation would likely occur via a remote attacker sending a crafted URL or form input to an unauthenticated or authenticated user. The impact is confined to the client side, allowing the execution of arbitrary JavaScript in the victim’s browser session.
OpenCVE Enrichment
EUVD