Impact
The CropRefine plugin fails to properly neutralize user‑supplied input before rendering it in a web page, allowing a reflected cross‑site scripting (XSS) attack. An attacker can inject malicious JavaScript that executes in the context of any user who views a crafted page—potentially hijacking sessions, defacing content, or redirecting to phishing sites. The vulnerability is purely a client‑side impact, affecting confidentiality, integrity, and availability of the user experience of any affected WordPress site.
Affected Systems
WordPress sites that have installed the ERA404 CropRefine plugin in any version from the initial release through version 1.2.1 are impacted. The plugin is listed under the ERA404 vendor and is commonly distributed via the WordPress plugin repository.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity reflected XSS. The EPSS score is less than 1%, indicating a very low probability that this vulnerability will be actively exploited in the near term. It is not catalogued in the CISA KEV list. The likely attack vector is a reflected XSS attack triggered when a user follows a malicious link or visits a crafted URL containing the vulnerable input, requiring user interaction to execute the payload. The exploit does not require authentication and can be delivered remotely via HTTP requests that include the malformed query.
OpenCVE Enrichment