Impact
The vulnerability is an improper neutralization of user input during web page generation, enabling an attacker to inject and execute arbitrary JavaScript in the victim’s browser. This DOM‑based XSS flaw could lead to session hijacking, defacement, or phishing attacks against site visitors. It is classified as CWE‑79.
Affected Systems
The Delay Redirects plugin developed by jagdish1o1 is affected. All releases up to and including version 1.0.0 are vulnerable; no higher versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 5.9 indicates a medium severity risk. The EPSS score of less than 1% suggests a very low likelihood of exploitation at present, and the vulnerability is not recorded in the CISA KEV catalog. The flaw can be triggered remotely by an attacker crafting a malicious URL that, when clicked by a site visitor, exploits the plugin’s unsanitized input handling to execute script in the user’s browser.
OpenCVE Enrichment