Impact
The Gloria Admin Panel plugin contains an improper neutralization of input during web page generation that permits a reflected cross‑site scripting (XSS) injection. By submitting a crafted value in a request parameter the attacker can have arbitrary scripts executed in the victim's browser, allowing theft of session cookies, defacement of the site, or execution of further malicious payloads. This vulnerability is a classic reflected XSS flaw categorized as CWE‑79.
Affected Systems
The flaw affects the Gloria Admin Panel plugin developed by bkninja for WordPress versions up to and including 1.3. All earlier releases are also vulnerable. The vulnerability is present in any installation that uses these affected plugin versions.
Risk and Exploitability
The CVSS base score of 7.1 indicates a medium‑to‑high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of an exploit probability figure does not reduce the risk. The attack vector is likely a crafted URL or form submission that a user will click or submit, making the exploitation scenario feasible on any site that does not restrict access. An attacker who succeeds could gain the victim’s browser privileges and potentially compromise the site’s integrity or user data.
OpenCVE Enrichment