Impact
Improper neutralization of input during web page generation, reflected use of user data without proper escaping, leads to a Cross‑Site Scripting (XSS) flaw in the DesignThemes Core Features plugin for WordPress. Attackers can inject malicious scripts into pages viewed by other users, enabling theft of session tokens, data exfiltration, or defacement.
Affected Systems
The vulnerability is present in the DesignThemes Core Features WordPress plugin, version 2.3 and earlier. It affects all installations of the plugin up to and including 2.3. No other versions were listed as affected.
Risk and Exploitability
The CVSS score is 7.1 indicating a high potential for exploitation. EPSS is less than 1%, suggesting low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is reflected XSS via plugin input fields or query parameters, inferred from the described lack of proper neutralization.
OpenCVE Enrichment