Impact
The vulnerability arises because the plugin fails to escape a user‑supplied value before inserting it into an HTML tag. This allows an attacker to embed arbitrary JavaScript that will execute in the browser of any user who loads the crafted page, including administrators. The impact is the ability to hijack sessions, deface sites, or deliver malware, compromising the confidentiality, integrity, and availability of the website's content and the users' interactions.
Affected Systems
This flaw affects the Five Star Restaurant Reviews WordPress plugin versions prior to 2.3.14. Any WordPress installation that has the plugin installed and has not been updated to 2.3.14 or later is potentially vulnerable.
Risk and Exploitability
The flaw is exploitable by unauthenticated attackers via a crafted HTTP request, meaning it can be triggered without login credentials. The exact CVSS score is not provided, but the nature of the flaw suggests a high risk of exploitation. Because no EPSS score is available and the vulnerability is not listed in CISA KEV, the precise exploitation probability is unknown; however, the widespread use of the plugin and lack of input sanitization make it a likely target for attack.
OpenCVE Enrichment