Impact
This vulnerability arises from an improper neutralization of input when generating a web page, enabling stored cross‑site scripting. An attacker can embed malicious scripts within WE Blocks content that will execute whenever the page is viewed, potentially allowing session hijacking, defacement, or data exfiltration. The weakness corresponds to CWE‑79, representing unsafe handling of user provided data.
Affected Systems
The issue affects the WordPress plugin WE Blocks by wordpresteem. All releases up to and including version 1.3.5 are vulnerable; earlier versions are also affected but the specific lower bound is not specified. Site administrators who have installed any of these versions are at risk.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as Medium severity, while the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker inserting malicious content through the plugin’s block editor, which is then stored and subsequently rendered to visitors. Exploitation requires that the plugin be installed and active on a publicly accessible WordPress site.
OpenCVE Enrichment
EUVD