Impact
Improper neutralization of input during web page generation allows reflected XSS, enabling an attacker to inject malicious scripts that execute in the victim’s browser.
Affected Systems
The vulnerability affects the WordPress plugin anmari amr cron manager (amr‑cron‑manager) up through version 2.3. Any WordPress site that has this plugin installed is potentially susceptible if the plugin has not been updated beyond the affected releases.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate severity, while the EPSS score of less than 1% reflects a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description this flaw involves reflected input and suggests a remote attack vector requiring a crafted URL that delivers the malicious payload to the victim’s browser.
OpenCVE Enrichment