Impact
The vulnerability is a reflected Cross‑Site Scripting flaw in the codepeople Search in Place plugin. Untrusted search input is rendered on the results page without proper escaping, allowing an attacker to inject arbitrary JavaScript that will execute in the victim’s browser. Because the input is reflected directly in the response, a malicious search query can trigger script execution, which may enable the attacker to manipulate page content or redirect the browser.
Affected Systems
WordPress installations running the codepeople Search in Place plugin version 1.5.5 or earlier are affected. The flaw is present from the earliest released version through 1.5.5. Administrators should identify sites that use this plugin and verify the installed version.
Risk and Exploitability
With a CVSS score of 7.1 the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known active exploitation as of the assessment date. An attacker can exploit the issue by crafting a malicious search query that is reflected in the plugin’s results page; no authentication is explicitly required. Based on the description, it is inferred that the search function is publicly accessible, allowing unauthenticated exploitation.
OpenCVE Enrichment