Impact
The vulnerability is a Cross‑Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into pages served by WordPress sites using the WP‑Recall plugin. This indicates a weakness in the plugin’s input handling and output encoding, which is identified as CWE‑79. Successfully exploited, it could enable session hijacking, cookie theft, defacement, or the execution of malicious code within the victim’s browser context.
Affected Systems
Any WordPress site that has the WP‑Recall plugin installed in a version from the earliest release up to and including 16.26.14 is vulnerable. The plugin is distributed under the codename tggfref:WP‑Recall.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1, placing it in the High severity range. Its EPSS score of less than 1% indicates a low probability of automated exploitation, yet the potential impact remains high due to the reflected nature of the XSS. The flaw is not listed in the CISA KEV catalog. Exploitation likely requires the attacker to craft a URL or input that is reflected back to the browser without proper sanitization, so a victim’s interaction with a malicious link or form would be necessary.
OpenCVE Enrichment
EUVD