Impact
Improper neutralization of input during web page generation in the Pets plugin allows an attacker to inject malicious scripts that are reflected back to the victim’s browser. The reflected XSS can lead to session hijacking, defacement, or malicious redirects, and the weakness is classified as CWE‑79.
Affected Systems
The Pets plugin for WordPress, developed by Igor Benic, is affected in all releases through version 1.4.1. The vulnerability applies to any WordPress site that installs these plugin versions and does not specify additional platform constraints.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity, while the EPSS score of less than 1% suggests a low exploitation probability at the current time. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a reflected XSS, inferred from the description of reflected input, which would require an attacker to supply crafted input via a URL or form parameter that the plugin fails to sanitize.
OpenCVE Enrichment