Impact
WordPress Tennis Court Bookings version 1.2.7 contains an improper neutralization of input during web page generation that permits reflected XSS. This flaw enables an attacker to embed malicious script in a crafted URL that, when opened by a victim, executes within the victim’s browser context, potentially allowing credential theft, session hijacking, or defacement. The weakness corresponds to CWE‑79 and manifests as a classic input validation issue.
Affected Systems
The vulnerability affects the EZiHosting Tennis Court Bookings WordPress plugin in all deployments up to and including version 1.2.7. No specific sub‑components are listed, so any installation of the plugin before 1.2.8 is exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is not yet cataloged in CISA's KEV list. Attacks rely on the victim clicking a crafted link or accessing a maliciously crafted URL, making it a reflected XSS vector that requires user interaction. If a user visits the vulnerable page with a malicious URL, the script runs immediately, establishing a high impact for that individual.
OpenCVE Enrichment
EUVD