Impact
Improper Neutralization of Input During Web Page Generation, known as Cross‑Site Scripting (CWE‑79), is present in the ViitorCloud Technologies Pvt Ltd Add Featured Image Custom Link plugin. The flaw allows an attacker to inject malicious JavaScript into pages rendered by the plugin, causing arbitrary script execution in the context of users who view the affected pages.
Affected Systems
All installations of ViitorCloud Technologies Pvt Ltd Add Featured Image Custom Link plugin version 2.0.0 and earlier are affected. The vulnerability is reported for versions from unspecified earlier releases through <= 2.0.0. Users running these versions are potentially exposed to the XSS flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.9, indicating moderate severity. The EPSS score is less than 1 %, implying a low probability of being publicly exploited today. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to entice users to visit a page that includes the plugin output, typically through social engineering or compromised content. Because it is a DOM‑based XSS, the flaw is client‑side and does not require authentication, meaning that publicly accessible pages are sufficient for exploitation.
OpenCVE Enrichment