Impact
An unauthenticated Cross‑Site Scripting flaw exists in the RadiusTheme Classified Listing WordPress plugin through version 5.4.2. The plugin does not properly neutralize user‑controlled input that is rendered in page output, allowing an attacker to embed malicious JavaScript into pages viewed by site visitors. This is a CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability. The flaw can be triggered by any user who accesses the site or submits content processed by the plugin, without requiring authentication.
Affected Systems
WordPress installations that use the RadiusTheme Classified Listing plugin version 5.4.2 or earlier are affected; newer plugin versions are not impacted.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high risk. Because the flaw does not require authentication, any visitor can trigger it by loading a crafted URL or submitting malicious data. The EPSS score of less than 1 % indicates a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog, implying no confirmed active exploitation reports.
OpenCVE Enrichment