Impact
Improper neutralization of input permits malicious scripts to be executed in a visitor’s browser, enabling defacement, credential theft, session hijacking or phishing. The vulnerability is a reflected XSS flaw, classified as CWE‑79, which can compromise confidentiality, integrity and availability of a site’s content.
Affected Systems
The WordPress Flexo Posts Manager plugin, developed by Flexostudio, is affected in all releases up to and including version 1.0001. Users running this plugin on their WordPress installations expose the site to the described XSS risk.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability presents a moderate to high severity. The EPSS score of <1% indicates a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit it via reflected XSS, typically by inserting malicious script into crafted URLs or form inputs, without needing authentication or elevated privileges.
OpenCVE Enrichment