Impact
The vulnerability is a DOM‑Based Cross‑Site Scripting flaw that allows malicious input to be rendered unescaped within a web page. An attacker exploiting the flaw could inject and execute arbitrary client‑side scripts in the browsers of users who visit affected WordPress sites, potentially leading to credential theft, session hijacking, or defacement of the site’s content. The weakness corresponds to CWE‑79, a classic input validation issue that permits code injection into web pages.
Affected Systems
The flaw affects the WordPress xili‑language plugin of the Michel‑xiligroup dev team. Versions from the initial release up through 2.21.3 are vulnerable. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity impact, while the EPSS score of less than 1 % signals a low probability of exploitation in the wild. The flaw is not currently listed in the CISA KEV catalog. The likely attack vector is a DOM‑based injection in user interfaces that call the plugin; an attacker would need to supply crafted input that the plugin renders without proper neutralization.
OpenCVE Enrichment
EUVD