Impact
The vulnerability in AI BotKit allows contributors or higher to store malicious scripts in the ‘id’ attribute of the ai_botkit_widget shortcode. This is a classic stored cross‑site scripting flaw (CWE‑79) that causes code injected by an authenticated user to run in the browsers of any visitor to pages that include the shortcode. Such execution can lead to credential theft, session hijacking, defacement, or further exploitation of the victim’s environment.
Affected Systems
The flaw exists in all released versions of the AI BotKit WordPress plugin up to and including 1.1.7. Plugins distributed by wisdmlabs are affected. Any WordPress site that has installed this plugin and has contributors or higher can be impacted.
Risk and Exploitability
The CVSS score of 6.4 places the issue in the moderate range. The EPSS score is below 1 %, indicating a low probability of exploitation at this moment, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires an authenticated user with a contributor role to insert or edit a shortcode that contains a malicious id value. Once the payload is stored, any user who views a page containing the shortcode will have the script executed in their browser.
OpenCVE Enrichment