Impact
The vulnerability is an improper neutralization of input that allows an attacker to store malicious scripting code in the plugin’s data. When a visitor loads the affected content, the browser will execute that code, potentially stealing cookies, hijacking sessions, defacing the site, or delivering other client‑side attacks. The weakness is a classic Stored XSS flaw (CWE‑79).
Affected Systems
The issue impacts the bPlugins All Embed – Elementor Addons plugin for WordPress, specifically all releases up to and including version 1.1.3. Any WordPress installation that has this plugin installed and has not applied a later update is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate‑to‑high severity, while the EPSS score of less than 1% suggests a low probability of exploitation relative to the broader threat landscape. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker inserting malicious input via the plugin’s administrative interface or other data entry points, which is then stored and rendered for all site visitors. Once the payload is stored, any visitor to the affected page will be exposed to the script execution risk.
OpenCVE Enrichment
EUVD