Impact
Improper Neutralization of Input During Web Page Generation ('Cross‑Site Scripting') vulnerability in ThemePunch Slider Revolution allows Reflected XSS, enabling an attacker to inject malicious scripts that execute in the browsers of site visitors when the affected plugin renders unsanitized input.
Affected Systems
The affected product is the WordPress Slider Revolution plugin from ThemePunch, covering all releases from 7.0.0 through 7.0.16. Any WordPress site that has installed one of these plugin versions user submits or accesses crafted input that the Slider Revolution plugin renders without proper escaping, a malicious script can be executed in the browser context of visitors.
Risk and Exploitability
The CVSS score of 7.1 class The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is inferred that a reflected XSS can be triggered by an attacker sending a crafted request containing malicious input—typically via a URL parameter or an untrusted form field—without requiring authentication or special privileges. The impact is limited to browsers of site visitors, but could be amplified if thesite cookies.
OpenCVE Enrichment