Impact
The Timeline Event History WordPress plugin is vulnerable to Reflected Cross‑Site Scripting via the ‘id’ parameter. Based on the description, inadequate input sanitization and lack of output escaping allow an unauthenticated attacker to inject JavaScript that will execute in a user’s browser when the crafted link is clicked, enabling phishing, cookie theft or other client‑side attacks in the victim’s context.
Affected Systems
Any installation of the wpdiscover:Timeline Event History plugin running a version up to and including 3.2 is affected. Users with earlier or later releases are not impacted by this specific flaw.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1% suggests a low but non-zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is a reflected web request; an attacker crafts a URL containing a malicious ‘id’ value, then lures a victim to click the link. Successful exploitation requires victim interaction but imposes no authentication or privileged conditions.
OpenCVE Enrichment