Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attackers to inject arbitrary scripts that execute in the victim’s browser. This reflected Cross‐Site Scripting can lead to session hijacking, credential theft, or defacement depending on the attacker’s goals. The weakness is classified as CWE‑79.
Affected Systems
The affected product is the WPManageNinja Fluent CRM plugin for WordPress. All versions through 3.1.7 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate‑to‑high severity. The EPSS score of less than 1% suggests that successful exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attack vector is reflected XSS via user‑supplied data supplied to the plugin, likely requiring user interaction such as clicking a link or submitting a form.
OpenCVE Enrichment