Impact
The vulnerability allows reflected cross‑site scripting because user input is not properly escaped when generating web pages. An attacker can inject arbitrary JavaScript that will execute in the context of any unsuspecting user who visits a crafted URL, potentially compromising the user’s session data, credentials, or other sensitive information.
Affected Systems
WordPress sites that use the WP Bulletin Board plugin from codebycarter, with all releases up to and including version 1.1.4 vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact level. The EPSS score of less than 1 % suggests a low but non‑zero probability that this flaw will be exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, meaning no confirmed active exploits have been reported. Based on the description, the likely attack vector is a crafted URL that includes malicious JavaScript payload, which can be leveraged by anyone who obtains a user’s browser access—no authentication is required.
OpenCVE Enrichment
EUVD