Impact
Improper neutralization of user input during web page generation allows attackers to inject malicious scripts that will execute in visitors' browsers. The reflected XSS flaw can be used to deface content, steal session cookies, or inject further malicious code, compromising confidentiality, integrity, or availability of the website.
Affected Systems
The vulnerability affects all releases of the Kreatura LayerSlider plugin for WordPress up to and including version 8.4.0. Any WordPress site running one of these versions is potentially exploitable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. EPSS is not available and the flaw is not listed in CISA’s KEV catalog. The likely attack vector is client‑side exploitation via crafted URLs or slider input fields that cause reflected scripts to run in a victim’s browser. An attacker who can supply such input or direct a user to a malicious link could achieve the impact described above.
OpenCVE Enrichment