Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject malicious JavaScript into a web page through improper neutralization of user input. In a typical scenario, the injected script runs in the victim’s browser, enabling actions such as session hijacking, cookie theft, or defacement of the site’s content. The flaw originates from the WebMan Amplifier plugin’s handling of user supplied data during page rendering.
Affected Systems
The issue affects the WebMan Amplifier plugin for WordPress developed by WebMan Design | Oliver Juhas. All releases from its initial version up to and including 1.5.12 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests that widespread exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Exploitation typically requires that a user visits a crafted URL or interacts with page content that triggers the injected script, so the attack vector is inferred to be user‑initiated web browsing. No authentication or privileged access is required to exploit the flaw.
OpenCVE Enrichment