Impact
Improper Neutralization of Input During Web Page Generation, also known as Cross‑Site Scripting (XSS), is present in the ThemePunch Slider Revolution plugin for WordPress. The flaw allows an attacker to inject malicious scripts that are rendered in the browsers of visitors when the plugin processes user‑supplied input without adequate escaping. The resulting impact is that any attacker who can embed crafted input in a request—typically through a URL parameter or form field—can cause arbitrary script execution in the victim’s browser, which may lead to session hijacking, defacement, or phishing within the context of the affected site.
Affected Systems
The vulnerability is confined to the WordPress Slider Revolution plugin versions 7.0.0 through 7.0.16. Any WordPress installation that has one of these releases installed is susceptible. The flaw is not limited to the core WordPress platform but specifically targets the Slider Revolution component provided by ThemePunch.
Risk and Exploitability
The CVSS score of 7.1 classifies this as high severity. An EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a reflected XSS that can be triggered by an attacker sending a crafted request containing malicious input—such as a malicious URL or form submission—to a site that hosts the affected plugin. No authentication or elevated privileges are required to exploit the weakness.
OpenCVE Enrichment