Impact
Based on the description, it is inferred that the flaw is triggered by user‑controlled input that is rendered in page output. An unauthenticated Cross‑Site Scripting flaw exists in the RadiusTheme Classified Listing WordPress plugin through version 5.4.2. The plugin does not properly neutralize user‑controlled input that is rendered in page output, allowing an attacker to embed malicious JavaScript into pages viewed by site visitors. This is a CWE-79: Impro flaw can be triggered by any user who accesses the site or submits content processed by the plugin, without requiring authentication.
Affected Systems
WordPress installations that use the RadiusTheme Classified Listing plugin version 5.4.2 or earlier are affected; newer plugin versions are not impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high risk. Because the flaw does not require authentication, any visitor can trigger it by loading a crafted URL or submitting malicious data. Based on the description, the likely attack vector involves any site visitor loading a crafted URL or submitting malicious data. The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed active exploitation reports.
OpenCVE Enrichment