Impact
The vulnerability in Walker Core permits an attacker to inject arbitrary client‑side scripts into web pages served by sites that have the plugin installed. This is a DOM-based XSS flaw that occurs when the plugin fails to neutralize input before rendering it. Successful exploitation can lead to session hijacking, credential theft, defacement, or the delivery of malicious payloads to end‑users.
Affected Systems
The flaw affects the Walker Core plugin from unknown versions through 1.3.17 installed on WordPress sites. Any site running the plugin before the published fix is vulnerable; newer versions are presumed corrected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve the plugin’s public interfaces, where unfiltered user input can be injected, and the vulnerability can be triggered via crafted URLs or form submissions that the plugin processes and reflects in the DOM.
OpenCVE Enrichment