Impact
WordPress is vulnerable to a pre‑auth reflected cross‑site scripting flaw on the login screen. In this flaw, a maliciously crafted URL can be inserted into a third‑party website, and when a victim clicks it the injected JavaScript runs within the context of the WordPress site. The attacker can exfiltrate session cookies or, with additional payloads, trigger a remote code execution path that executes with the privileges of the WordPress installation, thereby compromising confidentiality, integrity, and availability for users who interact with the malicious link. Based on the description it is inferred that the attack vector requires the victim to perform a social‑engineering trick and actively click the crafted link, which is typical for reflected XSS scenarios.
Affected Systems
All WordPress releases are affected. An update to WordPress 7.0.3 contains the fix, and the patch has been back‑ported to all branches back to 4.7. Therefore any site running a core version older than 7.0.3 remains vulnerable until it updates to a fixed release.
Risk and Exploitability
The CVSS score of 8.9 marks this vulnerability as high severity. The EPSS score is not available, so the current probability of exploitation is unknown, but the lack of a listing in the CISA KEV catalogue suggests no publicly known, targeted exploits have been observed yet. Attacks would require the victim to visit a malicious site, demonstrating social‑engineering reliance, yet with the reflected XSS the attacker can potentially gain full control of the affected WordPress site if successful.
OpenCVE Enrichment