Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attackers to inject arbitrary Javascript via reflected XSS. An attacker can craft a malicious URL or form payload that causes the browser to execute code in the context of the victim's session, enabling cookie theft, session hijacking, defacement or redirecting users to malicious sites.
Affected Systems
The flaw exists in the aBlocks WordPress plugin developed by Kodezen LLC. All releases from the earliest available version up to and including 2.16.0 are affected. Sites that have this plugin installed and serve it to visitors are vulnerable.
Risk and Exploitability
The CVSS score is 7.1, indicating high severity for client‑side impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The attack vector is public web‑based; no authentication is required. Exploitation is straightforward for malicious actors who can embed the offending payload in a link or web form, and users who click the link or submit the form will be affected.
OpenCVE Enrichment