Impact
The vulnerability allows an attacker to inject malicious script into web pages through improper input neutralization. The stored XSS flaw can be leveraged to execute arbitrary JavaScript in the browsers of users who view affected pages, potentially leading to cookie theft, session hijacking, or defacement. The weakness is a Classic Web Input Validation error (CWE‑79).
Affected Systems
The CodeBard Help Desk plugin for WordPress, versions up to and including 1.1.2, is affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. Attackers would most likely exploit it through stored input fields—such as ticket submission forms—where user-supplied data is rendered without proper escaping.
OpenCVE Enrichment
EUVD