Impact
The User Access Manager plugin for WordPress suffers from a reflected cross‑site scripting flaw, allowing an attacker to inject arbitrary script code through the tab_group_section request parameter. This weakness arises from a lack of input sanitization and output escaping. If an unsuspecting user clicks a crafted link, the malicious script executes within the victim’s browser, potentially hijacking the session, defacing the site, or stealing credentials. The flaw is catalogued as CWE‑79.
Affected Systems
The vulnerability affects installations of the User Access Manager plugin from any vendor version 2.3.18 or older, identified by the vendor gm_alex. All revisions through 2.3.18 contain the flaw; newer releases have addressed the issue.
Risk and Exploitability
The CVSS score of 6.1 classifies the risk as moderate, primarily due to the requirement of user interaction for exploitation. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that indicators of compromise are currently limited. Attackers could potentially craft malicious URLs that incorporate a compromised tab_group_section value, sending unsuspecting users to the infected page via email or social media. While no exploits have been publicly reported, the moderate score coupled with the need for user action warrants a prompt patch to avoid potential cross‑site scripting incidents.
OpenCVE Enrichment