Impact
The flaw is a DOM-based cross-site scripting vulnerability that occurs when the Better Search plugin fails to neutralize user input before rendering it in the browser. This allows an attacker to inject arbitrary JavaScript that will execute in the context of a victim’s browser when the affected page loads. The CVE description does not detail specific downstream effects, but the nature of the vulnerability means that any script that runs could carry out malicious activities as seen by the user.
Affected Systems
The issue affects the Ajay Better Search WordPress plugin on any WordPress site that uses version 4.1.0 or earlier. All releases from the earliest available version up through 4.1.0 contain the vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of <1% points to a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. It is inferred from the description of the flaw that an attacker would need the victim to visit a crafted link or otherwise interact with a URL containing malicious input, as is typical for DOM-based cross-site scripting.
OpenCVE Enrichment
EUVD