Impact
The GD Security Headers plugin for WordPress contains an improper neutralization of input during web page generation that allows reflected cross‑site scripting. When an attacker supplies crafted data, it is reflected back into a web page without sanitization, enabling the injection of arbitrary scripts that will execute in the victim browser.
Affected Systems
The vulnerability is present in the Milan Petrovic GD Security Headers plugin for WordPress in all releases up through version 1.8 inclusive. No later versions are known to be affected.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate‑to‑high severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the immediate future. The flaw is not listed in the CISA KEV catalog. Attackers can exploit this via a reflected XSS attack, requiring no authentication or privileged access, provided the plugin is active and the target site accepts external input.
OpenCVE Enrichment