Impact
The Web Directory Free WordPress plugin contains a DOM‑based cross‑site scripting flaw caused by improper neutralization of input during web page generation. An attacker can inject arbitrary JavaScript into a page rendered by the plugin, allowing client‑side script execution that can deface content, capture data or otherwise manipulate the user experience.
Affected Systems
Shamalli Web Directory Free plugins for WordPress versions up to and including 1.7.12 are affected. Any WordPress site that has a vulnerable instance of this plugin installed and activated is at risk; the flaw resides entirely in the plugin code and does not affect the core WordPress platform.
Risk and Exploitability
The base CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1 % suggests that exploitation is statistically uncommon at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the most plausible attack vector would involve a user visiting a page that incorporates attacker‑controlled input or a malicious link associated with the plugin; such interactions would trigger the DOM‑based XSS. Although no public exploits are documented, the potential impact on affected users justifies treating the flaw as a moderate threat until a fix is deployed.
OpenCVE Enrichment