Impact
The Pochipp plugin allows attackers to insert arbitrary scripts into the page by exploiting a reflected XSS flaw in the 'keyword' GET parameter. The lack of proper attribute escaping lets the payload appear in the search box value attribute. This flaw can lead to cookie theft, credential hijacking, or other malicious actions executed in the victim's browser. The weakness resides in inadequate output encoding and is classified as a reflected XSS vulnerability (CWE‑79).
Affected Systems
This issue affects the WordPress plugin Pochipp. All releases up to and including version 1.20.2 are vulnerable. Only systems running those versions of Pochipp on a WordPress installation are impacted.
Risk and Exploitability
The CVSS score is 6.1, indicating a medium severity risk. No EPSS information is available, and the flaw is not on the CISA KEV list, which suggests that widespread exploitation has not been observed. The vulnerability is accessible to unauthenticated users who can craft a malicious URL that will be rendered by a privileged user with the upload_files capability when they click a link or perform a media‑upload action. Because the attacker does not need authentication, the potential impact is limited to users who are tricked into performing that action.
OpenCVE Enrichment