Impact
The vulnerability arises because the WordPress plugin reflects the unescaped value of the 'page' parameter directly into an HTML attribute on a backend page. A crafted request can inject arbitrary JavaScript that executes in the context of any site administrator who follows the link, potentially allowing the attacker to steal admin cookies, manipulate the site, or perform actions using the administrator’s privileges.
Affected Systems
All installations of the ProSolution WP Client plugin for WordPress older than 2.0.11 are affected. The risk applies to any site that has the plugin activated and has its administrative area accessible to users who could receive a malicious link.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity that includes exploitation of a web application via an external user. The EPSS score of less than 1% suggests that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, if an attacker can influence an administrator to click a link, the lack of input sanitisation means the exploit is straightforward and requires no additional permissions or secrets. Most likely the attack vector is a request made through a web browser by delivering a crafted URL to the target administrator.
OpenCVE Enrichment