Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that permits reflected cross‑site scripting. An attacker can inject malicious scripts into the page output by manipulating input that is not properly encoded. This flaw is identified as CWE‑79. The primary impact is the potential compromise of user sessions, data theft, or delivery of malware to visitors of the site.
Affected Systems
The affected product is Infility Global, a WordPress plugin. Versions from the earliest available release through and including 2.15.06 are vulnerable. No further version details were provided.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is below 1%, suggesting an extremely low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS scenario where an attacker crafts a URL or form input that returns unsanitized data to the browser. Because it is reflected, an active attacker must have a URL that a victim clicks or submits input that triggers the vulnerable endpoint.
OpenCVE Enrichment
EUVD