Impact
Improper neutralization of input during web page generation allows a reflected cross‑site scripting vulnerability in the Bob Arigato Autoresponder and Newsletter plugin. The flaw permits injected scripts to be executed in a visitor’s browser when carefully crafted input is included in the response.
Affected Systems
Bob:Arigato Autoresponder and Newsletter plugin versions up through 2.7.2.4 are affected. Any WordPress installation running the plugin at or below this version is at risk. The plugin’s code processes user‑supplied data without proper escaping, leading to the reflected XSS condition.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating moderate‑to‑high severity. The EPSS score of less than 1% suggests a very low current probability of exploitation, and the issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can trigger the flaw from the public web interface by submitting input that contains script tags or JavaScript payloads, as no authentication or privileged access is required. The vulnerability remains primarily a security best‑practice concern until a patch is applied.
OpenCVE Enrichment
EUVD