Impact
Improper neutralization of user input in the Dooodl plugin causes reflected XSS when a crafted request reaches the site. The resulting injection can execute malicious scripts in the victim’s browser during page rendering. The specific consequences are not detailed in the CVE, but typical XSS effects may include browser‑based attacks. The impact is limited to the client side and depends on the user’s interaction with the malicious content.
Affected Systems
WordPress sites that have the noCreativity Dooodl plugin installed up to and including version 2.3.0 are affected. All earlier releases are also impacted, as the issue exists from the initial release up to and including 2.3.0. The vulnerability is triggered by any public HTTP request that passes unsanitized parameters to the plugin.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability is rated medium‑high. The EPSS score of less than 1% indicates that exploitation probability is currently very low, and the vulnerability is not listed in the CISA KEV catalog, meaning no widespread, confirmed exploits are publicly known. Based on the nature of XSS, the likely attack vector is web‑based and requires user interaction, such as navigating to a malicious link or submitting a crafted request. The potential impact remains client‑side and depends on the victim’s browsing activity.
OpenCVE Enrichment