Impact
An improper neutralization of user input during HTML generation enables the Authentication and xmlrpc log writer plugin to echo back unsanitized data, resulting in the execution of arbitrary JavaScript in the victim’s browser. This flaw is caused by the plugin’s failure to properly sanitize input before rendering it in a web page, and it aligns with the CWE‑79 Cross‑Site Scripting weakness type.
Affected Systems
WordPress sites that have installed the Authentication and xmlrpc log writer plugin by Federico Rota, with affected versions ranging from the initial release up to and including 1.2.2.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability, while the EPSS score of less than 1% reflects a low probability of active exploitation at the time of this analysis. The vulnerability is currently not listed in the CISA KEV catalog. Exploitation requires an attacker to persuade a site visitor to submit or load crafted data that the plugin reflects back, such as via a manipulated URL or form input. Successful exploitation would allow the attacker to run malicious code within the context of the visitor’s browser.
OpenCVE Enrichment
EUVD