Impact
The Reflector plugin for WordPress contains an improper neutralization of input vulnerability that allows attacker‑supplied data to be reflected unfiltered in the rendered page. This flaw is a classic Cross‑Site Scripting (CWE‑79) weakness that can enable malicious scripts to run in the context of any user who visits a crafted URL or interacts with a vulnerable form. Load‑time exploitation can lead to cookie theft, session hijacking, defacement, or the delivery of additional malware to unsuspecting visitors.
Affected Systems
All installations of the WordPress Reflector plugin with a version number of 1.2.2 or earlier are affected. The plugin is distributed by fox‑themes under the name "Reflector." No other WordPress plugins or core components are listed as impacted.
Risk and Exploitability
The vulnerability scores a CVSS base of 7.1, indicating moderate to high severity. The EPSS value is reported as less than 1 %, indicating a very low historic exploitation likelihood; however, the flaw remains publicly documented. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires that a user visits a specially crafted URL or submits a tampered form field, both of which can be trivially constructed by an attacker. Because the payload executes in the victim’s browser, the risk is confined to the rendering context of that user and does not affect server‑side state.
OpenCVE Enrichment