Impact
The vulnerability exists in the WP Bootstrap Tabs WordPress plugin because user‑supplied attributes of the bootstrap_tab shortcode are not properly sanitized or escaped. This permits authenticated contributors or higher to inject arbitrary JavaScript that is stored and then executed whenever a page with the shortcode is viewed. The flaw is a stored Cross‑Site Scripting vulnerability, classified as CWE‑79, and can allow attackers to deface content or steal session cookies in the victim’s browser.
Affected Systems
Any WordPress installation that has the virtus‑designs WP Bootstrap Tabs plugin installed with a version up to and including 1.0.4 is affected. The attack requires a user with contributor or higher rights who can insert or modify the bootstrap_tab shortcode.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation in the current environment. The vulnerability is not listed in CISA’s KEV catalog. Attackers need authenticated contributor access and the ability to add the bootstrap_tab shortcode; once inserted, the malicious script is served to all visitors of the vulnerable page, making the impact system‑wide while the attack vector remains user‑driven and non‑privileged beyond contributor rights.
OpenCVE Enrichment