Impact
The Fade Slider plugin for WordPress contains a reflected XSS flaw caused by improper neutralization of input during web page generation. The plugin includes unescaped user input in the page output, which allows an attacker to inject arbitrary client‑side scripts.
Affected Systems
WordPress sites that have installed the Fade Slider plugin by Anandaraj Balu version 2.5 or earlier. The vulnerability applies to all releases from the original version through 2.5; sites should confirm whether the plugin is installed and running any of those versions.
Risk and Exploitability
The CVSS score of 7.1 indicates a high exploitation risk, while the EPSS score of less than 1% suggests that active exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by directing a user to visit a page that contains crafted input, as the flaw is remote and requires user interaction typical of reflected XSS scenarios.
OpenCVE Enrichment