Impact
The vulnerability is an improper neutralization of input during web page generation that leads to DOM-based cross‑site scripting (XSS) in the calliko NPS computy plugin. An attacker can inject malicious client‑side scripts that are executed in the context of a victim’s browser, enabling potential session hijacking, defacement, or data theft. The weakness is identified as CWE‑79 and is limited to the web page rendering process.
Affected Systems
Vendors and products affected are calliko’s NPS computy WordPress plugin, versions from the initial release through 2.8.2 inclusive. This includes all installations that have not yet upgraded beyond 2.8.2.
Risk and Exploitability
The reported CVSS score of 7.1 indicates a high severity, but the EPSS is less than 1%, suggesting a low exploitation probability at the time of analysis. The vulnerability is listed as not in the CISA KEV catalog, reducing the likelihood of known exploit kits. Potential attacks require a victim to visit a crafted page or click a malicious link, which is typical for DOM‑based XSS. The risk therefore is moderate to high if user traffic is substantial, yet exploitation likelihood remains low.
OpenCVE Enrichment