Impact
CVE-2024-31119 is a DOM‑based Cross‑Site Scripting (XSS) vulnerability in the WordPress Special Box for Content plugin. The injection flaw arises from improper neutralization of user input during web page generation, allowing an attacker to execute arbitrary JavaScript in the context of a victim’s browser. As a result, an attacker could hijack user sessions, steal cookies, deface content, or redirect users to malicious sites. This weakness is catalogued as CWE‑79 and poses a direct threat to confidentiality and data integrity for all users who interact with the affected plugin.
Affected Systems
The vulnerability affects the Special Box for Content plugin by Vasilis Triantafyllou, specifically all versions from the earliest (n/a) through version 1.0. All WordPress installations that have installed this plugin and have not applied a patch or upgraded to a non‑vulnerable version are potentially impacted.
Risk and Exploitability
The CVSS score of 5.9 signifies moderate severity and the EPSS score is not available. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is an attacker crafting a malicious URL or form that injects payloads into the DOM when a victim visits a page containing the vulnerable plugin. No special privileges or authentication are required, which increases the risk for widespread exploitation.
OpenCVE Enrichment