Impact
The vulnerability is an improper neutralization of input during web page generation, allowing a DOM‑Based XSS flaw to be exploited. An attacker can deliver malicious JavaScript that runs in the context of a legitimate user’s browser, potentially stealing session credentials, defacing the site, or hijacking the user’s interactions. The vulnerability is classified as a medium‑severity flaw with a CVSS score of 6.5.
Affected Systems
The affected product is the WP Image Mask plugin by Bogdan Bendziukov. Versions from the earliest release up to and including 3.1.2 are vulnerable.
Risk and Exploitability
Because the flaw is a DOM‑Based XSS, exploitation typically requires an attacker to lure a victim into loading a crafted page or URL that contains malicious script via the plugin’s input fields or output. The EPSS score is listed as less than 1%, indicating a low but non‑zero probability of exploitation, and the vulnerability is not currently included in the CISA KEV catalog. The CVSS score of 6.5 reflects the medium impact on confidentiality and integrity, but the lack of remote code execution limits the overall risk compared to more severe flaws.
OpenCVE Enrichment
EUVD