Impact
The plugin fails to escape certain query‑string parameters that it reflects on an administrator page, enabling attackers to inject malicious scripts into the page rendering. A victim who is a logged‑in administrator who follows a specially crafted link could have that script executed in their browser context. The effect is that the attacker can run arbitrary JavaScript in the context of that administrator, potentially hijacking the session or modifying page content.
Affected Systems
WordPress users running the NextScripts: Social Networks Auto-Poster plugin version 4.4.8 or earlier are susceptible. The plugin is distributed by Unknown:NextScripts. No specific build numbers beyond the version qualifier are listed. All installations of the plugin prior to 4.4.8 remain affected.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate to high severity for a reflected XSS that requires the victim to be authenticated as an administrator. The EPSS score of less than 1% indicates that the likelihood of exploitation is low at present, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be web‑based; an attacker must craft a malicious URL that reflects query‑string parameters onto an admin page and entice an administrator to click it. Successful exploitation could occur without additional network privileges, but requires victim interaction.
OpenCVE Enrichment