Impact
The vulnerability is a reflected cross‑site scripting flaw that occurs when user‑supplied data is echoed back in the page without proper escaping. An attacker can inject arbitrary JavaScript that executes in the victim's browser when they view the affected page, potentially leading to session hijacking, credential theft, defacement, or other client‑side attacks.
Affected Systems
The CVE affects the WordPress CBX Accounting & Bookkeeping plugin developed by Sabuj Kundu. All releases up to and including version 1.3.14 are vulnerable and sites running any of these versions are at risk.
Risk and Exploitability
The CVSS score of 7.1 reflects a moderate to high severity. The EPSS score is below 1%, indicating that exploitation is currently unlikely and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the flaw is publicly reachable via crafted URLs or form inputs, does not require authentication, and the attack surface remains open for any visitor to the affected site.
OpenCVE Enrichment
EUVD