Impact
The vulnerability is an improper neutralization of input during web page generation, allowing attackers to store malicious scripts that will run when other users view affected pages. It is identified as CWE‑79 and results in stored cross‑site scripting.
Affected Systems
WordPress sites running ThemeHunk Vayu Blocks – Gutenberg Blocks for WordPress & WooCommerce versions up to and including 1.4.7 are affected. There is no broader vendor scope beyond this plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, where an attacker can inject harmful payloads that persist in stored content and execute when rendered by any user’s browser.
OpenCVE Enrichment
EUVD