Impact
The Mayosis Core WordPress plugin contains an unauthenticated reflected cross-site scripting flaw that allows attackers to inject arbitrary JavaScript into pages served to victims. The vulnerability stems from improper sanitization of user-supplied input and is classified as CWE-79. An attacker can craft a malicious URL or form that, when accessed by an end‑user, results in the execution of code in the victim’s browser, potentially leading to session hijacking, site defacement, or phishing attacks.
Affected Systems
Affected products are the Mayosis Core plugin by TeconceTheme. Versions up to and including 5.4.7 are impacted. No additional vendors or version ranges are listed in the CNA data, so any installation of the plugin at those or lower version numbers should be considered vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity and the lack of a KEV listing suggests this vulnerability has not yet been widely exploited, but the absence of an EPSS value means the exact likelihood remains unclear. Attackers could exploit the flaw by sending a victim a link or form that contains the malicious payload, and no authentication or elevated privileges are required. Because the vulnerability is reflected and depends on a user’s browser, the risk is most acute for sites that regularly receive traffic from untrusted sources.
OpenCVE Enrichment