Impact
The "IPGP Visitors Origin" WordPress plugin, when used in a version older than 1.6, fails to sanitise or escape user input that is reflected back in the HTTP response. This omission allows an attacker who can send a crafted request to inject malicious scripts that will be executed in the victim’s browser when the user follows a link to that request.
Affected Systems
Any WordPress site that has the "IPGP Visitors Origin" plugin installed with a version earlier than 1.6 is affected. Sites using the plugin in such a state will process the unsanitised visitor origin data and could expose users to reflected XSS when presented with a manipulated URL.
Risk and Exploitability
The flaw can be exploited by unauthenticated attackers; no administrative or privileged access is required. An attacker can construct a URL containing malicious payload and trick a user into visiting it, causing the script to run in the user’s browser. The CVSS score of 7.1 indicates a serious impact, the EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalogue. These metrics confirm that while exploitation is straightforward, the overall probability of exploitation remains low.
OpenCVE Enrichment