Impact
An attacker can exploit improper input sanitization in the Off‑Canvas Sidebars & Menus (Slidebars) plugin to insert malicious scripts into a web page. The reflected XSS flaw could allow the attacker to steal user credentials, deface content, or hijack sessions, compromising confidentiality and integrity of the site and its visitors.
Affected Systems
WordPress sites that have the Off‑Canvas Sidebars & Menus (Slidebars) plugin installed, specifically versions up to and including 0.5.8.4. Any WordPress installation incorporating this plugin version is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity vulnerability. The EPSS score of less than 1 % suggests a low but non‑zero probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a crafted URL or input field that is reflected back into the page without proper encoding, enabling script execution in the browser of a victim who visits the malicious link.
OpenCVE Enrichment
EUVD