Impact
This vulnerability results from improper neutralization of input during web page generation in weDevs Dokan Pro, allowing injected reflected JavaScript payloads to be executed in the browser of any visitor. Based on the description, it is inferred that an attacker can trigger the flaw by posting malicious data or using a specially crafted URL, without requiring authentication.
Affected Systems
WordPress sites that use the Dokan Pro plugin earlier than version 5.0.7 are impacted. Versions 5.0.7 and newer contain the necessary input sanitization and are considered fixed.
Risk and Exploitability
The CVSS base score of 7.1 reflects moderate-to-high severity. An EPSS of less than 1% indicates a low probability of widespread exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers can craft a malicious URL or submit malicious data via a publicly exposed form to trigger the XSS; no authentication or privileged access is required.
OpenCVE Enrichment