Impact
The vulnerability allows an attacker to inject malicious script content into the Notification for Telegram plugin without needing authentication. The injected script can execute in the context of site visitors, enabling cookie theft, session hijacking, or defacement, and is identified as a CWE‑79 flaw.
Affected Systems
WordPress sites that use the Notification for Telegram plugin from rainafarai with versions 3.5 or older are affected; the flaw is fixed in version 3.5.1 and later.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while the EPSS score of less than 1% indicates a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Because the XSS injection is unauthenticated, an attacker can trigger it through ordinary web requests such as loading a page containing the plugin or submitting a crafted message, making the attack vector broadly available.
OpenCVE Enrichment