Impact
The Meta Display Block plugin for WordPress contains an input sanitization flaw that permits stored XSS. Authenticated users with Contributor level or higher can inject malicious scripts that execute for any visitor to the affected page, enabling defacement, credential theft, or redirection. The weakness is classified as CWE‑79.
Affected Systems
The vulnerable product is the Meta Display Block plugin by bhargavbhandari90. All releases up to and including version 1.0.0 are affected; newer releases may contain a patch. WordPress sites that have installed the plugin and grant Contributor or higher roles are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while an EPSS score of < 1 % suggests a low current exploitation probability and the vulnerability is not listed in the CISA KEV catalog. However, because any authenticated contributor can inject scripts, the potential impact is broad. Attackers would require legitimate Contributor credentials, typically supplied by site administrators, to exploit this flaw. Remediation is therefore advisable even if exploitation currently appears low.
OpenCVE Enrichment