Impact
An input handling flaw in the WordPress 多说社会化评论框 plugin allows an attacker to embed malicious script code that is reflected back to users when comments are displayed. This Cross‑Site Scripting flaw enables the injection of client‑side scripts that can steal session cookies, deface the site, or redirect users to malicious destinations. The weakness stems from the improper neutralization of user‑supplied data before rendering it within a web page and is classified as CWE‑79.
Affected Systems
The vulnerability affects the 多说社会化评论框 plugin released by shen2, specifically all versions up to and including 1.2. The plugin is distributed as a WordPress plugin that can be installed on any WordPress site where it is enabled.
Risk and Exploitability
With a CVSS score of 7.1, the flaw is considered high severity; the EPSS score indicates a very low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vectors involve a crafted HTTP request that includes malicious JavaScript in a comment field or other user‑input point, which is then echoed back to rendering pages. Successful exploitation could lead to theft of authentication cookies or execution of arbitrary scripts in the context of logged‑in users.
OpenCVE Enrichment
EUVD