Impact
This vulnerability is a reflected Cross‑Site Scripting flaw caused by improper neutralization of input during web page generation. An attacker can supply malicious content that is reflected back to the browser, enabling the injection of arbitrary scripts into the victim’s session.
Affected Systems
The WordPress Ravpage plugin released by matiskiba is affected in all versions up to and including 2.33.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of less than 1% suggests exploitation attempts are currently rare, and the vulnerability is not listed in CISA’s KEV catalog. Attackers would exploit it by delivering a crafted URL or query to the plugin, which would echo the input back to the user’s browser. Because the flaw is reflected and does not alter server‑side state, it is typically used for phishing or session hijacking rather than malware delivery.
OpenCVE Enrichment