Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that allows an attacker to inject and execute arbitrary JavaScript in the victim's browser when a specially crafted URL is visited. This reflected XSS can be used to hijack sessions, deface content, or quietly exfiltrate credentials. The weakness is classified as CWE‑79 and carries a CVSS score of 7.1, indicating a high potential impact if exploited.
Affected Systems
WordPress sites using the Emu2 (Emu2‑Email‑Users‑2) plugin version 0.83b or earlier are affected. The plugin is distributed by Juergen Schulze under the Emu2 product, and the issue applies to all versions from the earliest release through the listed vulnerable release.
Risk and Exploitability
The exploitation requires a victim to click or load a crafted URL containing the malicious payload; no authentication or elevated privileges are needed. The EPSS score of less than 1% suggests a low current exploitation probability, and the vulnerability is not listed in CISA KEV. However, the potential impact of browser‑side script execution makes it a serious concern for administrators who rely on this plugin, especially when users have administrative accounts. The safest assumption is that an attacker with knowledge of the vulnerable plugin could craft a link and target users, so proactive remediation is advised.
OpenCVE Enrichment