Impact
Improper neutralization of input during web page generation in the Dan Rossiter Document Gallery plugin creates a reflected client-side script injection flaw (CWE-79). The likely attack vector is the delivery of a crafted URL or malicious form input that bypasses the plugin's input sanitization and is reflected in a gallery page. In practice, an attacker can inject arbitrary JavaScript that executes in the browser of any visitor who loads the compromised page. The CVSS rating of 7.1 indicates this flaw is of high severity.
Affected Systems
The flaw affects WordPress sites that have the Dan Rossiter Document Gallery plugin installed in versions up to and including 5.1.0. Any site using these plugin versions is susceptible to the reflected XSS flaw.
Risk and Exploitability
The EPSS score of less than 1% indicates a low but non-zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 7.1 signals high severity. The likely attack vector is inferred to involve the attacker supplying malicious input in a URL or form field that the plugin fails to sanitize. Because this is a reflected XSS, its impact is confined to the victim's browser session and does not allow direct system compromise.
OpenCVE Enrichment