Impact
The vulnerability is an improper neutralization of input during web page generation, enabling reflected cross‑site scripting. An attacker can embed arbitrary JavaScript via crafted input, which executes in the victim's browser when the affected page is viewed. The attacker can steal cookies, session data, deface the site or launch further phishing attacks, impacting confidentiality, integrity, and availability of user interactions.
Affected Systems
WordPress sites running Easy Social Easy‑Social‑Media plugin version 1.3 or earlier are affected. Any instance of the plugin deployed through the WordPress plugin repository or third‑party sources that has not been updated beyond 1.3 is at risk.
Risk and Exploitability
The CVSS score is 7.1, indicating a high impact with an exploitation requirement of a single local user interaction. The EPSS score is below 1 %, showing a low but non‑zero probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS that exploits unsanitized parameters in a public page of the plugin, requiring an attacker to craft and embed a malicious URL or form input that a victim will click or view.
OpenCVE Enrichment