Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw present in the NotificationX Pro WordPress plugin up to version 3.1.4. It allows an attacker to inject malicious JavaScript into web pages served by the site, potentially leading to session hijacking, defacement, or theft of sensitive data. This weakness is a typical CWE‑79 input validation problem where user–controlled data is reflected without proper sanitization.
Affected Systems
The affected product is NotificationX Pro, a WordPress plugin. All installations of version 3.1.4 or earlier are vulnerable. No further version detail is provided beyond the limiting threshold.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, while no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, suggesting moderate public exploitation risk. Attackers can exploit the flaw by delivering crafted input to any visitor of the affected site, as authentication is not required.
OpenCVE Enrichment