Impact
The Comments Capcha Box plugin fails to properly neutralize user‑supplied input before rendering it in a web page, giving an attacker the ability to inject script code that is executed in the browsers of users who view the affected comment form. The CVE description specifies that the flaw enables reflected XSS via the comment form; no further specific downstream consequences are detailed in the description.
Affected Systems
The vulnerability is present in the WordPress plugin Comments Capcha Box from digitalzoomstudio. It affects every release from the earliest available version through and including version 1.1. Any WordPress site that has this plugin installed and is running a version in that range is impacted.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity. The EPSS score of < 1% suggests that widespread exploitation is currently unlikely, and the flaw is not listed in the CISA KEV catalog. The most probable attack path involves an attacker embedding a malicious payload into a comment, which is then reflected back to browsers that view the comment page. No additional exploitation conditions are specified in the CVE data.
OpenCVE Enrichment
EUVD