Impact
The Geotargeting WP WordPress plugin prior to version 3.5.6.2 does not sanitise or escape user‑supplied parameters in its AJAX responses, which are served with an HTML content type. This allows unauthenticated attackers to deliver arbitrary scripts that execute within the victim’s browser, enabling session hijacking, credential theft, or site defacement. The vulnerability is a classic reflected XSS, classified as CWE‑79.
Affected Systems
WordPress sites running the Geotargeting WP plugin with a version older than 3.5.6.2 are affected. No vendor vendor information is available, but the plugin itself is the point of exploitation.
Risk and Exploitability
No CVSS score has been publicly disclosed, and EPSS data is unavailable, so the precise exploitation probability cannot be quantified. The bug is not listed in the CISA KEV catalog. Based on the description, it is inferred that any anonymous user can trigger the exploit by sending a crafted request to the plugin’s AJAX endpoint, making it readily exploitable from a remote location. The risk is significant due to the potential for phishing or credential compromise.
OpenCVE Enrichment