Impact
The vulnerability is an improper neutralization of input during web page generation that allows reflected cross‑site scripting. By supplying specially crafted data to the plugin, an attacker can inject arbitrary JavaScript into the generated page, resulting in client‑side code execution in the victim’s browser.
Affected Systems
The problem exists in the LambertGroup Image&Video FullScreen Background plugin for WordPress, affecting all releases from discovery up through version 1.6.7.
Risk and Exploitability
The CVSS base score of 7.1 marks it as high severity, while the EPSS score of less than 1 % indicates that exploit activity is currently rare and it is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the delivery of a crafted request—such as a link or form submission—that causes the plugin to echo unsanitized input back into the page. An attacker could thereby infect any user who visits the affected content; the potential consequences include theft of session credentials, defacement of the page, or redirection to malicious sites, though these effects are inferred from typical XSS results.
OpenCVE Enrichment