Impact
The problem stems from improper neutralization of user input during web page generation, which permits reflected cross‑site scripting in the Invelity SPS connect plugin. An attacker can send a crafted request that includes malicious JavaScript, causing the script to be echoed back into the page and executed in the context of the victim’s browser. This can enable arbitrary code execution within the user’s session and potentially lead to theft of sensitive data or alteration of page content.
Affected Systems
All releases of the WordPress Invelity SPS connect plugin, from the earliest unknown version through version 1.0.8 inclusive, are affected.
Risk and Exploitability
The CVSS score of 7.1 ranks this vulnerability as high severity. The EPSS score is below 1 %, indicating a very low current probability of widespread exploitation. It has not been listed in the CISA KEV catalog. The likely attack involves a crafted request to the plugin’s input handling routine; the vulnerability is reflected, so the malicious payload must be supplied with each request.
OpenCVE Enrichment