Impact
The Vulnerability is a reflected Cross‑Site Scripting flaw in the Schiocco Support Board WordPress plugin that permits an attacker to embed malicious script snippets in the web page shown to a visitor. Because the plugin fails to neutralize user supplied data before inserting it into the page, an attacker can trick a user into visiting a crafted URL or submitting a form, causing the script to execute with the victim’s browser privileges. This can lead to cookie theft, session hijacking, defacement or further phishing attacks.
Affected Systems
Schiocco:Support Board is the affected product. Any installation of the Support Board WordPress plugin with a version number of 3.8.0 or earlier is vulnerable. The CVE does not list specific WordPress core versions, so any site using the plugin in the stated range is considered affected.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, indicating a high severity level. The EPSS score is below 1%, suggesting that widespread exploitation is currently unlikely, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a remote web request that includes malicious input; an attacker would need to persuade a user to click or otherwise load the payload, making user interaction a prerequisite for exploitation.
OpenCVE Enrichment
EUVD