Impact
The vulnerability is a DOM-based Cross- Site Scripting flaw that occurs when the A WP Life Blog Filter plugin fails to neutralize user input during web page rendering. An attacker can supply a crafted URL or otherwise manipulate a page element so that malicious script code runs in the browser of any visitor. Such script execution could lead to session hijacking, credential theft, defacement, or the execution of further attacks within the victim’s browser context. The weakness is a classic input-validation issue classified as CWE-79.
Affected Systems
The flaw affects the A WP Life Blog Filter plugin for WordPress versions through and including 1.7.3. All earlier releases are also vulnerable. The product is listed as "A WP Life:Blog Filter" in the CNA data.
Risk and Exploitability
With a CVSS score of 6.5 the severity is moderate; the EPSS score of less than 1% indicates a very low but nonzero likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalogue. It is a DOM-based XSS, so the attack vector is typically browser-based and would require a victim to visit a crafted URL or view a page with malicious content served by the affected plugin. Given the moderate severity and low EPSS, the risk to organizations is manageable but not negligible, especially for sites where the plugin is exposed to untrusted users or content. Threat actors with low resources might still target high-traffic sites to use the XSS payload for phishing or token theft.
OpenCVE Enrichment