Impact
A DOM‑based XSS flaw allows an attacker to inject malicious script content that is executed in the browser of any user who visits a vulnerable page. The vulnerability arises from an improper neutralization of input during web page generation, enabling attackers to execute arbitrary JavaScript that can hijack sessions, deface content, or exfiltrate data through the victim’s browser.
Affected Systems
The flaw appears in the WordPress plugin "Analytics Germanized for Google Analytics" developed by PascalBajorat. All released versions through 1.6.2 are affected, with no fixes available in those releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS of less than 1% signals a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction or a compromised site to supply crafted input; no elevated privileges or network services are needed.
OpenCVE Enrichment