Impact
The HandL UTM Grabber plugin for WordPress contains an unauthenticated Cross‑Site Scripting flaw, classified as a CWE‑79 weakness, that allows an attacker to inject malicious scripts into pages served by the plugin.
Affected Systems
This vulnerability affects any WordPress site that has Haktan Suren’s HandL UTM Grabber plugin version 2.9.2 or earlier installed, regardless of the user’s role or permissions. Any visitor to the site can trigger the flaw, as the flaw is unauthenticated and does not require special privileges.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, while its EPSS score of < 1% shows a very low current exploitation probability. It is not listed in the CISA KEV catalog. The attack is unauthenticated and can be launched from any remote location. It is inferred that an attacker could deliver a malicious link or embed the vulnerable content in a page that a victim visits, making exploitation straightforward once the plugin is present on a live website.
OpenCVE Enrichment