Impact
Improper neutralization of input in the RS WP Book Showcase WordPress plugin allows DOM‑based cross‑site scripting, enabling an attacker to inject malicious code into pages rendered for users, potentially resulting in credential theft, defacement or phishing attacks.
Affected Systems
The vulnerability affects the RS WP Book Showcase plugin for WordPress, specifically all releases up to and including version 6.7.59.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS value of less than 1% suggests a low probability of exploitation in the wild. The plugin is not listed in the CISA KEV catalog, implying that no large‑scale attacks are currently known. The flaw is DOM‑based, so exploitation requires a victim to view a page generated by the plugin with crafted input, making it most likely an opportunistic threat rather than a widely automated exploit.
OpenCVE Enrichment
EUVD