Impact
The Debt.com Business in a Box plugin for WordPress contains a stored cross‑site scripting flaw in the configuration parameter of the lead_form shortcode. Because input is not properly sanitized or escaped, an attacker who can log in with Contributor or higher rights can embed arbitrary JavaScript that will run for any user who views an injected page, enabling theft of credentials, session hijacking, or other client‑side attacks.
Affected Systems
WordPress sites employing debtcom’s Debt.com Business in a Box plugin version 4.1.0 or earlier are affected. The plugin is available from the WordPress plugin repository under the vendor debtcom.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as moderate. The EPSS score of less than 1% indicates a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to possess Contributor‑level authentication, after which malicious script can be stored and served to all site visitors who view the affected page.
OpenCVE Enrichment