Impact
The HandL UTM Grabber plugin for WordPress contains an unauthenticated Cross‑Site Scripting flaw classified as CWE‑79. An attacker can inject malicious scripts into the plugin’s output, causing the script to execute in the browsers of any visitor who loads a affected page.
Affected Systems
This vulnerability affects every WordPress site that has the HandL UTM Grabber plugin version 2.9.2 or earlier installed, regardless of the site owner’s role or permissions. Any visitor to such a site can trigger the flaw, as it does not require authentication or special privileges.
Risk and Exploitability
The CVSS score is 7.1 and the EPSS score is < 1%, indicating a low current exploitation probability. The vulnerability is not listed in CISA KEV. Attackers can launch the exploit remotely from any location, typically by sending a malicious link or embedding the vulnerable content in a page that a victim visits, which makes exploitation relatively straightforward once the plugin is on a live site.
OpenCVE Enrichment