Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw caused by improper input neutralization in the Epeken All Kurir plugin. Attackers can inject arbitrary JavaScript into pages rendered by vulnerable installations, enabling session hijacking, defacement, or delivery of malware. This constitutes a medium‑severity flaw classified as CWE‑79.
Affected Systems
Affected are WordPress sites that have the Epeken All Kurir plugin version 2.0.1 or earlier. The vulnerability exists across the full range from the first release to 2.0.1. Administrators using this product should verify the plugin version and plan an upgrade.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as medium severity, while an EPSS score below 1 % implies a low probability of being actively exploited in the wild. The flaw is not listed in CISA’s KEV catalog. The likely attack vector involves an attacker crafting a URL or malicious link that, when opened by any user viewing the affected page, will cause script execution in that user’s browser. Because the vulnerability is triggered in the client, widespread exploitation requires convincing victims to visit a malicious page.
OpenCVE Enrichment
EUVD