Impact
The Tooltip plugin for WordPress contains a DOM‑based Cross‑Site Scripting flaw caused by failing to neutralize user input during page rendering, which is a CWE‑79 type vulnerability. Based on the description, it is inferred that an attacker who can supply crafted content that the plugin reflects into the browser can execute arbitrary JavaScript within the victim’s session, potentially leading to credential theft, account takeover, or manipulation of page content.
Affected Systems
Affected users run the Tooltip plugin developed by Haris Zulfiqar on WordPress installations. Versions up to and including 1.0.1 are vulnerable; all later releases are not known to be affected.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5, indicating moderate severity, and an EPSS score of less than 1%, suggesting a low probability of exploitation at present. It is not listed in the CISA KEV catalog. Attackers would need to inject malicious content into a field handled by the plugin and trigger a page load in the victim’s browser. The flaw is DOM‑based, meaning it is client‑side and can be exploited through a URL or a malicious link without requiring authentication.
OpenCVE Enrichment
EUVD