Impact
The WP Debugging plugin up to version 2.12.2 contains an unauthenticated Cross Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into pages rendered to visitors. This vulnerability is classified as CWE-79 and can lead to client-side code execution when a victim browser loads the affected page.
Affected Systems
WordPress sites that have the WP Debugging plugin (created by Andy Fragen) installed at version 2.12.2 or older. No other plugins or WordPress core components are reported as affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate-to-high severity. The EPSS score of < 1 % denotes a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV. Any external user can trigger the flaw to the site, causing unintended JavaScript to run in the browsers of site visitors.
OpenCVE Enrichment