Impact
The flaw is an improper neutralization of input that allows a reflected XSS injection when the plugin receives user-supplied data. An attacker can craft a URL or form input that contains malicious script, which is then executed in the context of an unsuspecting user’s browser. The injected code can steal session cookies, deface content, redirect the user, or perform other client‑side actions that compromise confidentiality and integrity of the site and its visitors.
Affected Systems
The vulnerability affects the LambertGroup Radio Player Shoutcast & Icecast plugin for WordPress, specifically all releases from the earliest available version through and including version 4.4.7.
Risk and Exploitability
The CVSS score of 7.1 indicates a high level of risk, while the EPSS of less than 1 % suggests that exploitation probability at the time of analysis is low. The plugin is not listed in the CISA KEV catalog. The attack vector is likely a web‑based delivery of a crafted request, requiring the victim to visit a malicious link or submit a malicious form that triggers the injection. No special privileges are needed for exploitation.
OpenCVE Enrichment
EUVD