Impact
The vulnerability is a Reflected Cross‑Site Scripting flaw caused by improper neutralization of user‑supplied input during web page generation. An attacker can embed malicious JavaScript that executes in the victim’s browser when the page is returned, allowing theft of session cookies, credential phishing, or the delivery of further malicious payloads. The flaw resides in the Testimonials Showcase plugin and can be triggered via crafted input such as URL parameters or form fields.
Affected Systems
WordPress sites that use the cmoreira Testimonials Showcase plugin version 1.9.16 or earlier. The plugin passes user input directly into page output without proper sanitization.
Risk and Exploitability
The CVSS score of 7.1 labels this a high‑severity issue, but the EPSS score of less than 1% indicates a very low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack path involves an attacker supplying malicious input that is reflected back in the HTTP response; the attack vector is web‑based input, such as injected parameters in URLs or form submissions.
OpenCVE Enrichment
EUVD