Impact
This defect represents an Improper Neutralization of Input During Web Page Generation that allows reflected cross‑site scripting in the Marco Milesi ANAC XML Bandi di Gara WordPress plugin. An attacker can inject JavaScript by manipulating input that is reflected in a page response, potentially executing in users’ browsers and leading to session hijacking, defacement, or data theft.
Affected Systems
Any WordPress site that has the ANAC XML Bandi di Gara plugin installed at version 7.7 or earlier, as this is the range reported by the vendor.
Risk and Exploitability
The CVSS score of 7.1 indicates substantial impact, while the EPSS score of less than 1% shows a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation would require an attacker to craft a request that embeds malicious code into a field processed by the plugin, which is then reflected back to the victim’s browser. Because no auxiliary conditions are mentioned, the attack vector is likely external and may be performed over HTTP/HTTPS without authentication.
OpenCVE Enrichment