Impact
The vulnerability in the azzaroco Ultimate Learning Pro WordPress plugin allows an attacker to inject malicious script through unsanitized input that is reflected back to the browser. This flaw can enable arbitrary JavaScript execution, which may be used to hijack user sessions, steal credentials, deface the site, or perform other client‑side attacks. The weakness is a classic input validation flaw categorized as CWE‑79.
Affected Systems
The azzaroco Ultimate Learning Pro plugin, versions up to and including 3.9.1, is vulnerable. Any WordPress site that has this plugin installed and enabled is potentially exposed, regardless of the site’s domain.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity if exploited. The EPSS score of less than 1% indicates a low probability of real‑world exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can likely trigger the reflected XSS by crafting a URL or form with malicious payload; the description infers that the flaw operates in a reflective manner and does not require authentication. Consequently, the attack vector is a reflected XSS against active visitors, with the scope limited to the sites hosting the vulnerable plugin.
OpenCVE Enrichment