Impact
The plugin contains an Improper Neutralization of Input During Web Page Generation flaw that allows attackers to inject and execute malicious scripts in a victim's browser. This Reflected Cross‑Site Scripting vulnerability can lead to session hijacking, credential theft, or site defacement from the victim's perspective.
Affected Systems
The flaw affects the WordPress plugin “افزونه پیامک حرفه ای فراز اس ام اس” developed by Faraz SMS. All versions from the initial release up to and including 2.7.3 are vulnerable. No other versions have been confirmed to be affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk, while an EPSS score of less than 1 % suggests that exploitation is currently rare. The vulnerability is not yet listed in CISA’s KEV catalogue. Based on the description, the likely attack vector involves embedding malicious code within a URL or form field that the plugin reflects back to the browser, so the attack requires the victim to load the crafted page. Because the flaw propagates user‑controlled data directly into the HTML response, it is straightforward for an attacker with access to the front‑end of the site to spin up malicious links.
OpenCVE Enrichment