Impact
The Search Atlas SEO WordPress plugin, versions up to 2.6.6, contains a reflected cross‑site scripting flaw that allows unauthenticated users to inject and execute arbitrary JavaScript in the browsers of site visitors. Based on the description, it is inferred that the plugin outputs search query parameters without sanitization. When a malicious URL is accessed by a visitor, the payload is executed within their browser session.
Affected Systems
The plugin is provided by Search Atlas Group as. All versions up to 2.6.6 are vulnerable. Any WordPress site that has the plugin installed at a vulnerable version is affected. Updating to 2.6.7 or later removes the flaw.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity, while the EPSS score of less than 1% indicates a low but non‑zero chance of exploitation. Attackers can trigger the flaw via unauthenticated HTTP requests to the plugin’s search interface; any user who visits a crafted search link will have the payload executed in their browser. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment