Impact
The Vzaar Media Management plugin for WordPress is vulnerable to reflected cross‑site scripting because the $_SERVER['PHP_SELF'] variable is echoed without proper sanitization or escaping. This omission allows unauthenticated attackers to embed malicious scripts in a URL, which are then reflected back to the victim’s browser when the link is visited. Such scripts can steal session data, deface the site, or serve other malicious payloads, but only execute when a user interacts with a crafted link.
Affected Systems
All installations of Vzaar Media Management up to and including version 1.2 are affected. The vulnerability exists in the plugin’s admin media upload script and requires a WordPress environment to operate.
Risk and Exploitability
The flaw carries a CVSS score of 5.3, indicating medium severity, and an EPSS score of less than 1%, suggesting low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation is limited to unauthenticated attackers who can lure a victim into clicking a malicious link; no privileged access or server-side code execution is required.
OpenCVE Enrichment