Impact
The H5P plugin for WordPress contains a reflected Cross Site Scripting flaw that does not require authentication. An attacker can inject arbitrary JavaScript into the page viewed by a victim, potentially enabling session hijacking, defacement, or phishing actions.
Affected Systems
WordPress sites running H5P plugin version 1.17.6 or earlier are affected. Version 1.17.7 and later contain the fix, so sites with older releases should upgrade immediately.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating high severity, and is not listed in the CISA KEV catalog. Although an EPSS score is not available, the lack of authentication and the reflected nature suggest it can be exploited easily by embedding malicious scripts in URLs or other input that the plugin echoes back to the browser. Successful exploitation results in client‑side code execution with the victim's privileges.
OpenCVE Enrichment