Impact
The Supermalink plugin for WordPress contains an improper neutralization of user‑supplied input during web page generation, leading to DOM‑based cross‑site scripting. An attacker can insert malicious scripts that execute in the victim’s browser when pages containing the vulnerable input are rendered, potentially hijacking sessions or defacing content. This weakness maps to CWE‑79.
Affected Systems
The vulnerability affects the ThanhD Supermalink plugin for WordPress. All releases from the initial version through 1.1 are vulnerable; any site using these versions is at risk. No specific sub‑product or component is singled out beyond the plugin itself.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is below 1 %, suggesting a low probability of exploitation in the wild, and the issue is not listed in CISA’s KEV catalog. The likely attack vector is a crafted URL or form input that the plugin processes, so the vulnerability is client‑side and requires a victim to visit a malicious link. An attacker could then execute arbitrary JavaScript in the victim’s context, compromising confidentiality, integrity, or availability of the site’s front‑end.
OpenCVE Enrichment
EUVD