Impact
The UberSlider Ultra plugin contains a reflected XSS flaw caused by improper neutralization of user input. When an attacker supplies specially crafted data – such as a query string or form entry – that data is echoed back to the page without sanitization. This allows the attacker to inject JavaScript that runs in the context of the site for any user who views the affected page, potentially stealing credentials, hijacking sessions, or delivering malware. The weakness is a classic input validation flaw (CWE‑79).
Affected Systems
Impact affects the LambertGroup UberSlider Ultra WordPress plugin versions up through 2.3, inclusive. Any WordPress installation using these plugin versions is vulnerable unless the plugin is removed or disabled.
Risk and Exploitability
The CVSS score of 7.1 places the issue in the high‑severity range. The EPSS score of < 1% indicates a very low but nonzero likelihood of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is remote, through a crafted URL or form submission visible to any site visitor, allowing an attacker to deliver malicious scripts to unsuspecting users.
OpenCVE Enrichment