Impact
The WordPress Simple URLs plugin, authored by Andrew Fiebert, contains a client‑side cross‑site scripting flaw as classified by CWE‑79. The flaw allows an attacker to inject arbitrary JavaScript into the plugin’s output, which is rendered in visitors’ browsers when the affected plugin processes user‑supplied data. The potential impacts include session hijacking, defacement, or redirection of site visitors, with the risk level reflected by a CVSS base score of 5.9.
Affected Systems
WordPress installations running Simple URLs plugin version 151 or earlier, authored by Andrew Fiebert, are affected. No other vendors or product variants are noted in the CVE report.
Risk and Exploitability
The EPSS score is reported at less than 1 %, indicating a very low likelihood of active exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 5.9 denotes medium risk for affected sites. Based on the description, the likely attack vector involves submitting crafted payloads through the plugin’s web interface, where unsanitized input is embedded into the page output, enabling an attacker to execute code in the context of the site’s visitors.
OpenCVE Enrichment