Impact
The flaw is an improper neutralization of input during web page generation in the School Management plugin, allowing reflected cross‑site scripting. Attackers can inject malicious scripts into data that is output back to the user’s browser without proper escaping, resulting in arbitrary script execution in the victim’s session.
Affected Systems
WordPress sites that use the mojoomla School Management plugin version 92.0.0 or older are affected. Versions newer than 92.0.0 have fixed the flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating high severity, but its EPSS score is below 1 %, suggesting a low likelihood of exploitation at present. The issue is not listed in CISA KEV. An attacker can exploit the flaw by supplying malicious input that is reflected in a generated page, causing the embedded script to run in the victim’s browser.
OpenCVE Enrichment
EUVD