Impact
The vulnerability is an improper neutralization of user input during web page generation, exposing the Institutions Directory plugin to reflected cross‑site scripting. An attacker can inject malicious JavaScript that is executed in the browsers of users who view recorded data within the plugin, potentially enabling session hijacking, defacement, or data exfiltration. The weakness is a classic reflected XSS flaw (CWE‑79).
Affected Systems
WordPress sites using the e‑plugins "Institutions Directory" plugin with versions up to and including 1.3.3. The advisory indicates vulnerability affects all versions from the initial release through 1.3.3.
Risk and Exploitability
The CVSS score of 7.1 gives it a high impact rating, yet the EPSS score of less than 1% suggests that exploitation is currently unlikely. The plugin is not listed in CISA’s KEV catalog, so no evidence of widespread exploitation. An attacker would need to supply a crafted request containing the malicious payload, usually via a link or form, to trigger the reflected script in a user’s browser.
OpenCVE Enrichment