Impact
The vulnerability is a classic DOM‑Based Cross‑Site Scripting flaw caused by improper neutralization of user input during web page generation. An attacker can inject and execute arbitrary JavaScript in the context of a victim's browser, which may lead to session hijacking, credential theft, or site defacement. The weakness is classified as CWE‑79, indicating an input validation error that is exploitable in the browser side.
Affected Systems
The flaw exists in the WordPress Adverts plugin provided by WPFactory, affecting all released versions up through 1.4. Users relying on these plugin releases are susceptible.
Risk and Exploitability
According to the CVSS score of 6.5 the flaw is of moderate severity. The EPSS score of less than 1% suggests a very low probability of real‑world exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote and requires the victim to visit a crafted URL or interact with malicious input that the plugin does not adequately sanitize. While exploitation is not widespread yet, the potential impact on confidentiality and integrity warrants a timely patch.
OpenCVE Enrichment
EUVD