Impact
The vulnerability is a reflected cross‑site scripting flaw caused by improper neutralization of user input during web page generation in the Pinpoll plugin for WordPress. Because the plugin echoes user‑supplied data without sanitization, an attacker can inject arbitrary JavaScript that runs in the browsers of visitors who load a crafted URL. This allows attackers to steal session cookies, deface the site, or perform phishing attacks, thereby harming the confidentiality and integrity of user data.
Affected Systems
Affected systems are WordPress installations that have the Pinpoll plugin installed at any version up through 4.0.0. The flaw is present across all releases from the earliest available version to 4.0.0 inclusive.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity impact. The EPSS score of less than 1% means that, as of the latest assessment, the probability of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to send a malicious link to a victim or entice the victim to visit a crafted page; because it is a reflected XSS, the exploitation requires the victim to click the link.
OpenCVE Enrichment