Impact
This flaw is a DOM‑based XSS in the WordPress WP Mail plugin caused by improper neutralisation of payloads that are rendered in a web page. If a malicious user supplies crafted input that is not encoded or escaped, scripts execute in the context of the site and can steal session data, hijack accounts, deface pages or perform other client‑side attacks. The vulnerability is limited to the browser, so it does not grant direct server compromise.
Affected Systems
All installations of the WordPress WP Mail plugin by the vendor mndpsingh287 published up to and including version 1.3 are vulnerable. Earlier releases are assumed to be affected as the range is listed as "n/a through <= 1.3".
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as a moderate risk. The EPSS score of less than 1% indicates that overall exploitation probability is low, and the vulnerability is not listed in the CISA KEV catalogue. The likely attack vector requires an attacker to supply malicious input that the plugin renders in the page; therefore the exposure is limited to users who view the affected page or who interact with the plugin’s interfaces.
OpenCVE Enrichment
EUVD