Impact
The BizLibrary WordPress plugin contains an improper neutralization of input during page generation that allows attackers to inject malicious script when a victim visits a crafted URL. This is a reflected XSS vulnerability (CWE‑79). The injected script can steal cookies, deface content, or redirect users, compromising any user who accesses the affected page.
Affected Systems
All installations of the Matthew BizLibrary plugin version 1.1 or earlier on WordPress sites. These plugins are commonly used for event or booking features and are deployed on sites that have not yet applied the latest version.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate severity level. The EPSS score is below 1 %, suggesting that exploitation attempts are expected to be rare and the vulnerability is not currently catalogued in CISA’s KEV. Until a fix is applied, an attacker can embed a malicious script into URLs that are reflected by the plugin, enabling the script to execute in the victim’s browser.
OpenCVE Enrichment
EUVD