Impact
The WP Smart Flexslider plugin for WordPress, released by Rajan Vijayan, contains an improper neutralization of input during web page generation that enables a reflected cross‑site scripting flaw. By embedding malicious JavaScript into a request that the plugin renders, an attacker can cause arbitrary script execution in the victim’s browser when the page is viewed.
Affected Systems
The vulnerability is present in all releases of WP Smart Flexslider up through version 2.5. WordPress sites that have installed this plugin version range are susceptible.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity impact, while the EPSS score of less than 1% indicates a low anticipated exploitation likelihood. This issue is not listed in the CISA KEV catalogue. The likely attack vector is reflected, in which an attacker crafts a malicious URL or input that is reflected back into the page and triggers execution of the embedded script once a user visits the page.
OpenCVE Enrichment