Impact
The "IPGP Visitors Origin" WordPress plugin, when used in a version older than 1.6, fails to sanitise or escape user input that is reflected back in the HTTP response. This omission allows an attacker who can send a crafted request to inject malicious scripts that will be executed in the victim’s browser when the user follows a link to that request.
Affected Systems
Any WordPress site that has the "IPGP Visitors Origin" plugin installed with a version earlier than 1.6 is affected. Sites using the plugin in such a state will process the unsanitised visitor origin data and could expose users to reflected XSS when presented with a manipulated URL.
Risk and Exploitability
The flaw can be exploited by unauthenticated attackers; no administrative or privileged access is required. An attacker can construct a URL containing malicious payload and trick a user into visiting it, causing the script to run in the user’s browser. No EPSS or KEV data are available, and a CVSS score is not provided, so the risk is evaluated entirely from the described impact and the lack of input sanitisation, which makes exploitation straightforward.
OpenCVE Enrichment