Impact
The vulnerability is a reflected cross‑site scripting flaw caused by improper input sanitization in the WordPress Super Logos Showcase plugin. Unsanitized data supplied via user‑controlled input is injected into the HTML response, allowing an attacker to execute arbitrary JavaScript in the context of a victim’s browser. Successful exploitation could lead to credential theft, session hijacking, defacement, or malicious redirects, affecting the confidentiality, integrity, and availability of the affected WordPress site for users.
Affected Systems
The issue impacts the highwarden Super Logos Showcase WordPress plugin version 2.8 and earlier. Any WordPress website that has the plugin installed at these versions is vulnerable, regardless of other security measures.
Risk and Exploitability
The CVSS score of 7.1 indicates severe risk for user interactions. The EPSS score of < 1% suggests a low probability of exploitation in the wild at present, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to craft a malicious request or URL that includes unsanitized user input, and the victim must load the affected page. Once executed, the injected script runs with the privileges of the victim browser, enabling a range of attacks outlined above. The vulnerability is considered a high‑impact problem for sites where user input is displayed and should be addressed promptly.
OpenCVE Enrichment