Impact
The vulnerability is an improper neutralization of input during web page generation that allows DOM‑based XSS. An attacker can inject malicious scripts that execute in the context of victims who view pages generated by Penci Recipe. The impact is limited to the scope of the user’s browser; an attacker can manipulate the page content or cause the browser to access unintended resources, otherwise confining the effect to client‑side execution.
Affected Systems
PenciDesign’s Penci Recipe plugin. All releases published up to and including version 4.0 are impacted. No further version detail is specified, but any installation of the plugin before 4.1 is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. The EPSS score of less than 1 % suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. DOM‑based XSS typically requires the victim to visit a crafted URL or interact with plugin content, so the attack vector is likely a user clicking a malicious link.
OpenCVE Enrichment
EUVD