Impact
Improper neutralization of input during web page generation in the BoldGrid Sprout Clients plugin allows an attacker to inject malicious scripts that are reflected back to the user’s browser. If an attacker crafts a URL containing malicious payloads and lures a victim into visiting the URL, the script will run in the victim’s browser context. This can be used to steal session cookies, hijack accounts, deface content, or perform phishing attacks against users who view the affected page.
Affected Systems
WordPress sites running the BoldGrid Sprout Clients plugin version 3.2.1 or earlier are affected. The vulnerability is present in all releases through that version.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for this reflected XSS flaw. The EPSS score of less than 1% suggests a very low probability of widespread exploitation at the time of assessment, and it is not listed in the CISA KEV catalog. The attack vector is client‑side, requiring the victim to visit a crafted URL; no special privileges are needed on the server. An attacker could therefore target any user, including administrators, without prior access to the site’s backend.
OpenCVE Enrichment