Impact
The vulnerability arises from insufficient sanitization of user input in the SEO Pyramid plugin, allowing an attacker to inject malicious script via a reflected XSS payload. This flaw can deliver arbitrary JavaScript into the web pages rendered by the plugin, which may lead to session hijacking, phishing, or defacement when unsuspecting visitors load the affected page.
Affected Systems
WordPress sites that have installed the SEO Pyramid plugin developed by Chibueze Okechukwu. Versions from the earliest known release up to and including 1.9.8 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact if exploited, while the EPSS score of less than 1% suggests that automated exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require the attacker to craft a malicious URL or payload that is reflected back to a visitor’s browser, which is feasible through standard web interaction without special privileges.
OpenCVE Enrichment