Impact
The PRIMER by chloédigital plugin contains an improper neutralization of input during web page generation that permits a reflected XSS flaw. An attacker can embed malicious scripts into requests that the plugin processes without proper escaping, leading to execution in the victim’s browser and potential data theft or defacement. The weakness is categorized as CWE‑79.
Affected Systems
All releases of the chloédigital PRIMER plugin from the first version through version 1.0.25 are affected. No other vendors or products are listed.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high impact if exploited. The EPSS score is below 1 %, suggesting a low probability of exploitation in the near term, and it is not listed in the CISA KEV catalog. Likely attack vectors involve a victim clicking a crafted link or submitting a form that triggers the plugin’s unsanitized output, resulting in script execution on the victim’s browser.
OpenCVE Enrichment