Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw caused by incorrect neutralization of user input during webpage generation in the Valenti Engine plugin. An attacker can inject malicious JavaScript that runs with the privileges of any visitor to the affected page, allowing cookie theft, session hijacking, or defacement of the site content.
Affected Systems
WordPress installations that employ the codetipi Valenti Engine plugin, in all versions up through 1.0.3, are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a high severity, while the EPSS score of less than 1% shows a very low likelihood of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered simply by loading a crafted page or by visiting an affected page, and it does not require authentication or privileged access.
OpenCVE Enrichment