Impact
Improper neutralization of user input allows stored XSS in Phi Phan Content Blocks Builder plugin up to version 2.7.6. Based on the description, it is inferred that the vulnerability enables an attacker to inject malicious scripts that are persisted within page content and executed whenever anyone views the affected page, potentially resulting in session hijacking, cookie theft, defacement, or other browser‑side attacks. CWE‑79 underlies the flaw.
Affected Systems
The vulnerability affects WordPress sites that have the Content Blocks Builder plugin by Phi Phan installed, specifically any version from the plugin's initial release through 2.7.6.
Risk and Exploitability
With a CVSS score of 6.5 and an EPSS of less than 1 %, the statistical likelihood of exploitation is low, and the issue is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack typically requires an attacker to submit malicious content via the plugin’s content creation interface; sites that allow public or untrusted user submissions are at higher risk. Once injected, the payload is persisted, so it impacts all users who load the compromised page. No remote code execution or system‑level compromise is achieved, but the attack can undermine trust and lead to secondary attacks if users interact with the injected scripts.
OpenCVE Enrichment
EUVD