Impact
Improper neutralization of user input during web page generation in the mojoomla School Management plugin allows reflected XSS. The flaw permits the injection of arbitrary client‑side scripts that are reflected back to the user, potentially altering the content of the page that the victim sees. This weakness is a classic input validation issue, identified as CWE-79.
Affected Systems
The School Management plugin for WordPress, produced by mojoomla, is vulnerable in all versions from unspecified starting point up to and including 92.0.0. Any WordPress site that has the plugin installed at a version ≤ 92.0.0 is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is reported as less than 1%, suggesting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack likely requires that a victim view a page containing reflected user‑supplied data, which could be provided via a crafted URL or form input.
OpenCVE Enrichment
EUVD