Impact
The Payflex Payment Gateway plugin for WordPress contains an improper neutralization of input during web page generation, leading to reflected Cross‑Site Scripting. This flaw allows an attacker to inject and execute arbitrary scripts in the browser of any user who views a crafted page, potentially enabling session hijacking, credential theft, or malicious defacement. The weakness is defined as CWE-79.
Affected Systems
The vulnerability affects the Tomlister Payflex Payment Gateway WordPress plugin in all releases up to and including version 2.7.1. Users of earlier or later releases are not impacted.
Risk and Exploitability
With a CVSS score of 7.1, the issue is classified as high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation at the time of this analysis. The attack vector is web‑based and generally requires a victim to click a maliciously crafted link or visit a page containing injected script payloads, a scenario that is often feasible in social engineering contexts. Given the lack of exploit proofs, the immediate risk is moderate to high for sites that have not applied the patch.
OpenCVE Enrichment