Impact
The wpCAS plugin includes a reflected Cross‑Site Scripting flaw caused by improper neutralization of user input in generated web pages. An attacker can supply crafted URLs or form data that embeds malicious JavaScript, which the plugin outputs without sanitization. When a victim views the affected page, their browser executes the injected script, potentially stealing authentication tokens, manipulating page content, or redirecting to phishing sites. This attack compromises the confidentiality and integrity of the site’s users but does not affect the server’s internal state directly.
Affected Systems
WordPress sites running the Casey Bisson wpCAS plugin version 1.07 or earlier are affected. The vulnerability is present from the earliest version through 1.07 inclusive.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a high‑severity weakness, while the EPSS value of less than 1% indicates that exploitation is currently unlikely but possible. The vulnerability is not yet listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a reflected XSS via user input in the web interface; an attacker would need to craft a malicious request and lure a user to visit it.
OpenCVE Enrichment