Impact
The vulnerability is an unauthenticated Cross‑Site Scripting flaw that exists in Do Lasso plugin versions 358 and earlier. The weakness allows a malicious actor to inject arbitrary JavaScript into web pages rendered by the plugin. An attacker could steal session cookies, deface the site, or spread additional malware, all of which compromise confidentiality and integrity of the web application. The weakness corresponds to CWE‑79, where insufficient output encoding or sanitization opens a path to script injection.
Affected Systems
Any WordPress installation that has Lasso Analytics, Inc.'s Do Lasso plugin version 358 or older deployed is affected. No specific WordPress core version is noted, so any site running the vulnerable plugin is at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The exploit probability (EPSS) is not available, and the vulnerability is not listed in CISA's KEV catalog. Because the flaw is unauthenticated, the likely attack vector is a direct page request to a page where the plugin outputs user‑supplied content. Without additional defensive controls, exploitation does not require privileged access to the server.
OpenCVE Enrichment