Impact
This vulnerability is an instance of Improper Neutralization of Input During Web Page Generation (CWE‑79). An attacker can supply malicious input that is reflected in the browser without proper encoding, enabling the execution of arbitrary scripts in the context of the victim’s session. The impact includes the potential theft of cookies, session hijacking, and the execution of attacker's code within the victim’s browser, which can lead to defacement, phishing, or further network compromise.
Affected Systems
The affected product is the WordPress Scroll UP plugin released by King Rayhan. Versions from the earliest release through version 2.0 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of less than 1 % suggests very low but non‑zero exploit probability at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely reflected input through user-supplied parameters, such as URL query strings or form fields, and requires no authentication. Exploitation would involve an attacker crafting a malicious link that a victim follows, causing script execution in the victim’s browser.
OpenCVE Enrichment
EUVD