Impact
This vulnerability is an Improper Neutralization of Input during Web Page Generation that allows a reflected Cross‑Site Scripting (XSS) flaw. The flaw occurs when the UDesign Core plugin fails to properly escape user‑controlled input before rendering it in a response, potentially enabling an attacker to inject arbitrary client‑side scripts. Such scripts run with the privileges of the victim, permitting defacement, credential theft, or session hijacking within the context of the affected WordPress site.
Affected Systems
The weakness affects the AndonDesign UDesign Core WordPress plugin versions up to and including 4.14.0. Systems running the plugin in this version range—on any WordPress installation—are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% suggests that the probability of discovery and exploitation remains low. The vulnerability is not listed in the CISA KEV catalog. Attackers can likely exploit this by delivering a crafted URL to a user, with the reflected script executing when the victim loads the page. The impact is limited to the victim browser; no remote code execution or system‑wide compromise is possible unless the user runs malicious code locally.
OpenCVE Enrichment