Impact
The hiWeb Migration Simple plugin for WordPress contains a reflected Cross‑Site Scripting flaw that permits attackers to inject arbitrary JavaScript via the 'new_domain' query parameter. The plugin fails to sanitize or escape the parameter before reflecting it back to the page, allowing a crafted URL to deliver malicious script to a victim. When a site administrator clicks such a link, the code executes in the administrator's browser, potentially exposing session cookies, login credentials, or enabling further phishing attacks.
Affected Systems
The vulnerability affects the hiWeb Migration Simple plugin developed by den‑media for WordPress. All releases up to and including version 2.0.0.1 are impacted. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.1 classifies the issue as moderate severity. Exploitation does not require authentication; an attacker only needs to persuade an administrator to click a malicious link, making the attack a social‑engineering vector. The EPSS score is currently unavailable and the flaw is not listed in the CISA KEV catalog, indicating no known widespread exploitation yet. Nonetheless, any WordPress site running a vulnerable instance of the plugin should remediate promptly to close the opportunity for malicious script execution.
OpenCVE Enrichment