Impact
Improper neutralization of input during web page generation allows reflected XSS. When user‑supplied data is included in a page without proper sanitization, an attacker can embed malicious script that is executed in the victim’s browser.
Affected Systems
Softwebmedia Gyan Elements plugin for WordPress is affected. All installations with a version equal to or older than 2.2.1 may be vulnerable. No specific sub‑versions beyond 2.2.1 are listed, so any release dated n/a through 2.2.1 is included.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The likely attack vector is a web request containing malicious input from an unauthenticated user, typically delivered via a crafted URL or form field. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the high CVSS suggests timely remediation is prudent.
OpenCVE Enrichment