Impact
The vulnerability is a reflected cross‑site scripting flaw caused by improper neutralization of user inputs in the Astoundify Listify WordPress plugin. An attacker can embed malicious scripts that will execute in the browsers of visitors who view a crafted URL or form input. This can result in session hijacking, defacement, or delivery of phishing content to affected users.
Affected Systems
The flaw affects all installations of the Astoundify Listify WordPress plugin with a version number of 3.2.5 or earlier. These include every site that has not yet upgraded past 3.2.5.
Risk and Exploitability
The flaw receives a CVSS score of 7.1, indicating high severity. The EPSS score is below 1 %, suggesting that current exploitation attempts are rare, and the flaw is not listed in the CISA KEV catalog. The vulnerability is a reflected XSS, so the likely attack vector is via a crafted URL or form input that is reflected unescaped back to the victim. Exploitation would require an unsuspecting user to click a link or otherwise load the page containing the malicious input, allowing the injected script to run in their privileged browser context.
OpenCVE Enrichment