Impact
The Page Builder by SiteOrigin plugin for WordPress contains a stored Cross‑Site Scripting flaw in the Embedded Video (PB) widget that is triggered only when an authenticated user of Contributor level or higher injects arbitrary scripts into the widget’s data. When a page containing the malicious content is viewed, the script runs in the context of the visitor’s browser, creating opportunities for session hijacking, defacement, or theft of sensitive information. The vulnerability is a classic example of insufficient input sanitization and output escaping (CWE‑79).
Affected Systems
WordPress sites that have the Page Builder by SiteOrigin plugin installed, any version up to and including 2.31.4. The affected product is the SiteOrigin Page Builder plugin, and the flaw manifests when the Embedded Video widget is used.
Risk and Exploitability
With a CVSS base score of 6.4 and an EPSS probability of less than 1 %, exploitation is of moderate severity but low likelihood. The vulnerability is not listed in CISA’s KEV catalog. Attack requires authenticated access at the Contributor level or higher, and the malformed widget data is stored and replayed each time the page is loaded, making the impact persistent for all users who visit the affected page.
OpenCVE Enrichment
EUVD