Impact
Improper neutralization of input in the Categories Images plugin permits a DOM‑Based XSS flaw. An attacker can embed malicious JavaScript that executes in a victim’s browser when the victim visits a page that includes the vulnerable plugin. The impact is the ability to run arbitrary scripts in the context of the site, potentially enabling data theft, session hijacking, or the delivery of further malware.
Affected Systems
The vulnerability affects all releases of the Categories Images plugin up to and including version 3.3.1. The plugin is maintained by the vendor Zahlan.
Risk and Exploitability
CVSS score 6.5, EPSS score < 1%, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through crafted URLs or input fields that trigger the DOM‑based XSS. The attacker must entice a user to visit a malicious link or interact with a malicious input on the vulnerable site. Once executed, the script can compromise confidentiality, integrity, and availability of the affected WordPress installation.
OpenCVE Enrichment