Impact
The Alert Box Block plugin stores user supplied content without proper sanitization, creating a stored cross‑site scripting flaw where arbitrary JavaScript can be injected into the page. When a visitor loads a page containing an infected alert box, the injected script runs in that user’s browser, which can lead to cookie theft, credential harvesting, defacement, or the execution of malicious actions on behalf of the visitor. This is a classic input validation weakness identified as CWE‑79.
Affected Systems
All versions of the bPlugins Alert Box Block – Display notice/alerts in the front end up to and including 1.1.0 are vulnerable. Any WordPress site running one of these plugin releases is impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of widespread exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need the ability to provide content to an alert box, typically by having sufficient permissions to create or edit one. Once the malicious payload is stored, it affects every visitor who views the page containing the alert box, making it a moderate risk for sites with public reach.
OpenCVE Enrichment
EUVD