Impact
The vulnerability is a Cross‑Site Scripting (XSS) flaw that occurs because the Simple Payment plugin does not properly neutralize user input before rendering it in web pages. An attacker who can influence the content of the plugin’s output can inject malicious scripts that run in the browser of any user who views the affected page. Successful exploitation could lead to session hijacking, theft of credentials, defacement or other malicious activity in the victim’s browser. The flaw is identified as CWE‑79.
Affected Systems
WordPress sites running the Simple Payment plugin by Ido Kobelkowsky with version 2.4.6 or earlier are impacted. No other plugins or core WordPress versions are explicitly affected according to the CVE data.
Risk and Exploitability
The reported CVSS score is 7.1, indicating moderate to high severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack likely requires a user to view a page that includes the plugin’s output, so a remote or public attacker can influence the input or construct a malicious URL that triggers the flaw.
OpenCVE Enrichment