Impact
This vulnerability is an improper neutralization of input during web page generation, allowing reflected XSS. An attacker can inject malicious scripts that execute in the victim’s browser.
Affected Systems
The affected product is the WordPress WP Test Email plugin released by Boopathi Rajan. All releases up to and including version 1.1.7 are vulnerable; newer releases are not known to be affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score is less than 1%, indicating the probability of exploitation is currently low, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote via a crafted HTTP request that provides malicious input to the plugin’s input handling.
OpenCVE Enrichment