Impact
This vulnerability is a reflected XSS flaw identified as CWE-79. The My Custom Widgets plugin processes user-supplied input without proper neutralization before rendering it in a page. An unauthenticated user can inject arbitrary JavaScript into the generated content, potentially redirecting users, exfiltrating session data or performing phishing attacks.
Affected Systems
The affected plugin is Janekniefeldt My Custom Widgets, version 2.0.5 and earlier. Any WordPress site that has installed or activated this plugin is susceptible. No other vendors are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium-to-high severity. The EPSS score of less than 1% suggests low likelihood of exploitation at the moment. The vulnerability is not registered in the CISA KEV catalog. It is a reflected XSS flaw; the attack vector is likely through any user-visible parameter or query string that the plugin passes to the page without encoding. An attacker does not need special privileges to trigger the flaw, so the impact can affect all site visitors.
OpenCVE Enrichment
EUVD