Impact
The VikRestaurants WordPress plugin contains a flaw in which user input is not properly neutralized before being included in generated HTML, allowing reflected cross‑site scripting. This vulnerability enables an attacker to inject and execute arbitrary JavaScript when a victim loads a crafted page.
Affected Systems
The vulnerability affects the e4jvikwp VikRestaurants WordPress plugin in all releases up to and including version 1.5.2. Site owners using any of those versions are exposed until they upgrade to a newer release that addresses the input sanitization issue.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. It is inferred that the attack vector is via a crafted request that incorporates malicious input into the plugin’s output; exploitation requires only the victim’s interaction and no special conditions.
OpenCVE Enrichment