Impact
The flaw is a DOM‑Based XSS that occurs when the plugin fails to neutralize user supplied data before rendering it on a web page. An attacker can construct malicious input that is then displayed to a victim browser, enabling the execution of arbitrary scripts. This can be used for defacement, cookie theft, or other client‑side attacks. No additional impacts beyond script execution are documented in the description.
Affected Systems
The WordPress plugin tagDiv Opt‑In Builder, versions up to and including 1.7.4, is affected. No other products or platforms are listed as impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 7.1 reflects a high severity for the DOM‑Based XSS flaw. The EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker is likely to deliver malicious input through the plugin’s forms or configuration fields, which is then rendered to any user that views the affected page.
OpenCVE Enrichment