Impact
The vulnerable plugin accepts unsanitized user input that is reflected back into the generated web page, allowing attackers to inject malicious JavaScript. This reflected XSS flaw can compromise the confidentiality and integrity of a victim’s session and can be used to plant malicious code, steal credentials, or deface the site. The weakness is a classic example of CWE‑79, where improper neutralization of input during web page generation creates an injection vector.
Affected Systems
QuanticaLabs CSS3 Vertical Web Pricing Tables plugin for WordPress, versions up to and including 1.9. The vulnerability impacts all installations of this plugin that have not been updated beyond 1.9, regardless of the WordPress version.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity vulnerability. The EPSS score of less than 1% suggests a low estimated probability of exploitation at this time, and the vulnerability is not currently listed in CISA’s KEV catalog. Nonetheless, reflected XSS can be triggered via crafted URLs or form submissions, meaning an attacker can exploit the flaw remotely against any user who visits a malicious link or interacts with the plugin’s interfaces.
OpenCVE Enrichment
EUVD