Impact
Improper neutralization of input during web page generation allows reflected XSS, enabling attackers to execute arbitrary JavaScript in the context of the victim’s browser, potentially leading to session hijacking, defacement, or phishing attacks.
Affected Systems
The WordPress Lawyer Directory plugin from e-plugins, versions up to and including 1.3.2, is affected. All users of this plugin should review the plugin version and apply any available updates.
Risk and Exploitability
With a CVSS score of 7.1 and an EPSS score below 1%, the vulnerability is considered medium severity and is unlikely to be widely exploited, though it is still not listed in KEV. The attack vector is reflected XSS, typically exploiting user-supplied input that is not properly sanitized. An attacker can embed malicious script in a crafted URL or input field, which when visited by a user, executes in that user's browser context.
OpenCVE Enrichment