Impact
The vulnerability is an improper neutralization of input during web page generation, allowing reflected XSS in the WordPress Section Widget plugin. Attackers can inject arbitrary JavaScript that runs in the victim’s browser when they view a page containing the forged request. This can lead to session hijacking, defacement, data theft, and other client‑side compromise through the affected user’s browser.
Affected Systems
WordPress plugin Section Widget (ctltwp), versions up to and including 3.3.1 are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests a low but non‑negligible exploit likelihood. This issue is not listed in the CISA KEV catalog. The attack most likely proceeds via a crafted URL or form that injects malicious script into the page, exploiting the lack of proper input sanitization.
OpenCVE Enrichment
EUVD