Impact
A reflected XSS flaw exists in the Magic Slider plug‑in where user‑provided content is reflected in web pages without proper neutralization, allowing attackers to inject malicious scripts that execute in the browser of any user who visits a crafted URL.
Affected Systems
The vulnerability impacts the LambertGroup Magic Slider plug‑in for WordPress, affecting all versions up to and including 2.2.
Risk and Exploitability
The CVSS score of 7.1 rates it as a high‑severity issue and the EPSS score of less than 1% indicates a low likelihood of exploitation at the time of analysis. It is not listed in the CISA KEV catalog. Attackers are likely to exploit it by delivering a malicious link that contains crafted query parameters or form inputs that are reflected back in the page, requiring victim interaction to trigger the payload.
OpenCVE Enrichment