Impact
This vulnerability arises from improper neutralization of input during web page generation, allowing reflected XSS attacks. An attacker can craft malicious input that is echoed back in a response, injecting executable scripts into the victim’s browser. Such execution can lead to session hijacking, credential theft, defacement, or other client‑side compromises, as documented by CWE‑79.
Affected Systems
The VeronaLabs WP Statistics plugin for WordPress, versions up through 14.16.14, are vulnerable. The latest patch is version 14.16.15 and later.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a crafted URL that, when visited by a user, reflects malicious input into the browser. Attackers could embed the URL in emails, social media, or other channels to reach unsuspecting users.
OpenCVE Enrichment