Impact
Improper neutralization of input during browser page generation allows an attacker to inject malicious JavaScript through the Google +1 Button plugin, resulting in a DOM‑based cross‑site scripting flaw. The vulnerability can lead to client‑side code execution, enabling attackers to steal session cookies, deface pages, or conduct phishing attacks against visitors.
Affected Systems
The flaw affects the WordPress plugin Peadig’s Google +1 Button by Alex Moss. Any installation running version 0.1.2 or earlier is susceptible; versions newer than 0.1.2 are not impacted.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as high, while an EPSS score of less than 1% indicates a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog. Attackers would need to supply malicious content that the plugin processes, likely via the button’s click event, to exploit the DOM‑based XSS.
OpenCVE Enrichment
EUVD