Impact
The Hyve Lite plugin stores user input unchanged into web pages, resulting in a stored XSS flaw that an attacker can exploit to run arbitrary JavaScript in browsers viewing the compromised pages. This allows cookie theft, session hijacking, defacement, or other malicious actions carried out in the victim’s context.
Affected Systems
Themeisle AI Chatbot for WordPress – Hyve Lite plugin versions up to and including 1.2.2 are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 5.9 and an EPSS score below 1 %, indicating moderate severity and a low likelihood of exploitation. It is not listed in the CISA KEV catalogue. Exploitation would typically occur through a web‑based input field that persists data for subsequent page loads, making the attack surface broad across site visitors.
OpenCVE Enrichment
EUVD