Impact
The vulnerability is a DOM‑Based Cross‑Site Scripting flaw in the Ohio Extra WordPress plugin. Improper neutralization of input during web page generation allows an attacker to inject malicious scripts that run in the victim’s browser. A successful exploit could enable session hijacking, credential theft, defacement, or delivery of additional malware, compromising the confidentiality and integrity of user data and potentially the entire WordPress site. The weakness is classified as CWE‑79.
Affected Systems
The affected product is Ohio Extra from colabrio. All versions up to and including 3.6.0 are vulnerable; newer releases are not affected. No specific operating system or PHP version is mentioned, so any installation running these plugin versions is at risk.
Risk and Exploitability
The CVSS score for this flaw is 6.5, indicating moderate severity. The EPSS score of less than 1% suggests that exploitation is not frequently observed, and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is through the plugin’s web interface, where user‑supplied data is reflected into the DOM without proper sanitization. An attacker can craft a specially‑formatted URL or form input that injects malicious JavaScript, which the victim’s browser then executes.
OpenCVE Enrichment