Impact
Unauthenticated Cross Site Scripting occurs in the GetGenie WordPress plugin for versions 4.4.3 and earlier. The flaw allows an attacker to inject arbitrary HTML or JavaScript into the page output on any page served by the plugin. Because it does not require authentication, any visitor can trigger it, potentially enabling malicious script execution in the browsers of site visitors.
Affected Systems
The vulnerability affects the GetGenie plugin released by Roxnor. It is present in all versions up to and including 4.4.3, which can be installed on any WordPress site that includes this plugin.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw does not require authentication, any visitor to the site can trigger it, potentially allowing attackers to inject malicious scripts into the output.
OpenCVE Enrichment