Impact
The vulnerability is an improper neutralization of input during web page generation that allows reflected cross‐site scripting. An attacker can supply malicious input, which is echoed back in the page, enabling the execution of arbitrary scripts in the browser of any user who views the affected content. This can lead to session hijacking, defacement, or malicious payload delivery. The weakness aligns with CWE‑79.
Affected Systems
The WordPress Ultimate Reviews plugin from Rustaurius, version 3.2.14 and earlier, is affected. Users running any of these releases may be vulnerable if the plugin is publicly accessible.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score is below 1 % and the issue is not listed in CISA KEV, indicating a low current exploitation probability. The likely attack vector is remote via a crafted piece of input, such as a review or comment field, that an attacker can insert into a URL or form, reflected back to the victim's browser. An attacker does not need prior authentication, so any website that allows unfiltered user input through the plugin could be targeted.
OpenCVE Enrichment
EUVD