Impact
The vulnerability is an improper neutralization of user input in the WordPress Auto Spinner plugin, enabling a reflected cross‑site scripting attack. An attacker can craft a URL that injects malicious scripts into the browser rendering the page, potentially hijacking sessions or defacing content. This flaw does not directly compromise server secrets but can impact user confidentiality and integrity of the web session.
Affected Systems
ValvePress WordPress Auto Spinner plugin, all released versions up to and including 3.26.0. Users running the plugin on any WordPress installation are at risk.
Risk and Exploitability
With a CVSS score of 7.1, the flaw presents moderate to high risk. The EPSS score shows less than 1% probability of exploitation, and the flaw is not currently listed in CISA KEV catalog. The attack vector is reflected, requiring an attacker to lure a user to a crafted URL or embedded content. No authentication or elevated privileges are needed to trigger the vulnerability.
OpenCVE Enrichment
EUVD