Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in the Under Construction WordPress plugin. By injecting malicious JavaScript or HTML, an attacker can trick visitors into executing code in their browsers, potentially leading to phishing, malware delivery, or defacement. This is classified as CWE‑79.
Affected Systems
Any WordPress installation using the UnderConstructionPage "Under Construction" plugin version 5.82 or earlier is affected. The official fix is to upgrade to version 5.83 or later, which removes the vulnerable code paths.
Risk and Exploitability
The CVSS base score of 7.1 denotes moderate severity. Since no EPSS score is provided, the exact exploitation probability is unknown. Based on the fact that the flaw is unauthenticated, it is inferred that an attacker could trigger it by simply visiting the site. The vulnerability is not listed in CISA KEV. However, the official fix—upgrading to plugin version 5.83 or newer—is available, reducing risk if applied promptly.
OpenCVE Enrichment