Impact
The iMoney WordPress plugin has an improper neutralization of input during web page generation, allowing attackers to inject malicious scripts via reflected XSS. The vulnerability enables arbitrary script execution in the victim browser when unsanitized input is reflected back in a page, potentially compromising the user experience.
Affected Systems
WordPress installations that have the itex iMoney plugin version 0.36 or earlier installed are affected. The issue applies to all releases from the plugin’s inception up to and including 0.36.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, but the EPSS score of less than 1% signals a low current likelihood of exploitation and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a reflected XSS attack where an attacker crafts a malicious URL containing unsanitized input that is reflected back in the page displayed to a user. Successful exploitation requires user interaction with the crafted link.
OpenCVE Enrichment