Impact
Improper neutralization of input during web page generation in the Educare plugin allows attackers to inject arbitrary scripts into a page. The reflected cross‑site scripting flaw can execute malicious code in the context of a victim’s browser, potentially leading to session hijacking, data theft, or defacement of the site. The weakness is a standard input‑validation error classified as CWE‑79.
Affected Systems
The vulnerability affects FixBD Educare plugin versions from the earliest available release through 1.6.1. Users running version 1.6.1 or older are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. The likely attack vector is a reflected XSS: an attacker crafts a malicious URL that the plugin processes and delivers to a user’s browser. Because the flaw is not persistent, an active user interaction with the crafted link is required.
OpenCVE Enrichment