Impact
Based on the description, the vulnerability is an unauthenticated Cross‑Site Scripting flaw (CWE‑79) in the WordPress ReviewX plugin for versions up to 2.3.10, permitting attacker‑controlled data to be rendered as part of the HTML output and enabling arbitrary client‑side scripts to execute.
Affected Systems
Any WordPress site that has installed the ReviewX plugin at or below version 2.3.10 is vulnerable. Sites running version 2.3.11 or newer have the available patch and are not affected.
Risk and Exploitability
The CVSS score of 7.1 classifies this flaw as high severity. The EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, so no known public exploits have been reported. Based on the description, the likely attack vector is any unauthenticated user who can access the vulnerable pages and inject malicious scripts by supplying crafted input through the plugin’s interfaces. While the expected exploitation probability is low, the high severity indicates that successful exploitation could lead to client‑side script execution in the context of the site’s front end.
OpenCVE Enrichment