Impact
This vulnerability arises from improper sanitization of the User‑Agent header during a failed login attempt. When an unauthenticated user supplies a crafted User‑Agent string, the plugin stores it in the database and subsequently renders it in an admin page without escaping, allowing arbitrary JavaScript to run in the browsers of anyone who loads that page. The injected script can steal session cookies, deface the site, or perform other malicious actions on behalf of the victim.
Affected Systems
The issue affects the Vigilant – 100% Free Security Suite WordPress plugin, all releases up to and including version 2.10.2. Any WordPress installation utilizing this plugin is susceptible, regardless of the underlying WordPress version.
Risk and Exploitability
With a CVSS base score of 7.2, the vulnerability represents a high‑risk flaw. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, yet any attacker who can send a HTTP request with a malicious User‑Agent header can achieve persistence without authentication. The attack vector is straightforward: an unauthenticated external user posts a crafted header, the plugin stores it, and all subsequent users of the affected page are exposed to the embedded script. Given that the exploit requires no further interaction from the attacker, the likelihood of exploitation is significant.
OpenCVE Enrichment