Impact
The vulnerability is an unauthenticated cross‑site scripting flaw in the SliceWP WordPress plugin up to version 1.2.10. It allows an attacker to inject arbitrary JavaScript that will execute in the browsers of visitors who access content from a site running the vulnerable plugin.
Affected Systems
WordPress sites that have the iova.mihai SliceWP plugin version 1.2.10 or earlier installed. No other products or vendor versions are listed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity for this XSS flaw. Attackers do not need to authenticate to exploit it, and any user who views affected content can be impacted. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because of the high potential impact of arbitrary script execution, the risk is significant for WordPress sites that have the SliceWP plugin enabled.
OpenCVE Enrichment