Impact
The Bold pagos en linea plugin contains a DOM‑Based Cross‑Site Scripting flaw caused by improper input neutralization. A crafted request can inject arbitrary JavaScript that runs in the victim's browser, enabling data theft, session hijacking, or phishing. The weakness is classified as CWE‑79.
Affected Systems
All installations of the Bold pagos en linea plugin version 3.1.4 or earlier are affected. The vulnerability exists in every release before 3.1.5.
Risk and Exploitability
The CVSS score of 7.1 indicates a high‑severity client‑side vulnerability. The EPSS score of less than 1 % points to a low likelihood of exploitation, and the issue is not listed in CISA’s KEV catalog. The likely attack path requires an attacker to supply malicious input—such as a specially crafted query string or link—to the plugin’s URL, which is then reflected into the page. Although the flaw is client‑side, the widespread use of WordPress sites means many users could be affected by a single malicious link.
OpenCVE Enrichment
EUVD