Impact
The vulnerability is an improper neutralization of input during web page generation, allowing reflected XSS. Attackers can inject arbitrary JavaScript that is reflected to victim browsers. The flaw is identified as CWE‑79.
Affected Systems
The affected product is the Eli Anti‑Malware Security and Brute‑Force Firewall plugin for WordPress, versions up to and including 4.23.89. The flaw affects all earlier releases as well.
Risk and Exploitability
The CVSS score of 5.8 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers could craft a malicious URL that does not require authentication; the victim only needs to access the crafted link for the script to execute.
OpenCVE Enrichment