Impact
The vulnerability stems from improper neutralization of input during page generation, allowing reflected XSS injection. A malicious actor can supply crafted data that the plugin echoes back, enabling the injection of arbitrary HTML or JavaScript. This could lead to defacement, session hijacking, credential theft, or execution of additional attacks against users who view the compromised page. The weakness is a classic input‑validation flaw (CWE‑79).
Affected Systems
WordPress sites that have installed the LambertGroup SHOUT – HTML5 Radio Player With Ads – ShoutCast and IceCast Support plugin the latest released version of which is 3.5.4 or lower. The vulnerability tracks all earlier releases back to the earliest version in the plugin’s chronology.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% denotes a very low exploitation probability under normal circumstances, and the vulnerability is not listed in the CISA KEV catalog. The attack pathway would most likely involve a reflected request that embeds malicious payloads into a parameter processed by the plugin – for example, a search or radio request that is echoed unfiltered. Because the vulnerability is reflected, it can be triggered simply by visiting a crafted URL, making it highly accessible to attackers with no special access rights.
OpenCVE Enrichment
EUVD