Impact
WordPress is vulnerable to a pre‑auth reflected XSS flaw on the login screen (CWE‑79). In this flaw, a maliciously crafted URL can be inserted into a third‑party website, and when a victim clicks it the injected JavaScript runs within the context of the WordPress site. The attacker can exfiltrate session cookies or, with additional payloads, trigger a remote code execution path that executes with the privileges of the WordPress installation, thereby compromising confidentiality, integrity, and availability for users who interact with the malicious link. Based on the description it is inferred that the attack vector requires the victim to perform a social‑engineering trick and actively click the crafted link, which is typical for reflected XSS scenarios.
Affected Systems
All WordPress releases are affected. An update to WordPress 7.0.3 contains the fix, and the patch has been back‑ported to all branches back to 4.7. Therefore any site running a core version older than 7.0.3 remains vulnerable until it updates to a fixed release.
Risk and Exploitability
The CVSS score of 8.9 marks this vulnerability as high severity. The EPSS score is 31%, indicating a reasonably high likelihood of exploitation, although no publicly known, targeted exploits have yet appeared in the CISA KEV catalogue. Attacks would require the victim to visit a malicious site, demonstrating social‑engineering reliance, yet with the reflected XSS the attacker can potentially gain full control of the affected WordPress site if successful.
OpenCVE Enrichment
Debian DSA