Impact
Improper neutralization of user input during page rendering allows malicious scripts to be stored by the Bootstrap collapse plugin and later displayed to site visitors. The flaw is a stored cross‑site scripting vulnerability, categorized as CWE‑79. This defect enables an attacker to embed code that will run in the browsers of any user who views the stored content.
Affected Systems
WordPress sites that use the Bootstrap collapse plugin from its initial release up through version 1.0.4, which is provided by sureshdsk. All releases in that range are affected.
Risk and Exploitability
The CVSS score of 7.1 signals a high severity risk, while the EPSS score of less than 1% indicates a low current likelihood of exploitation. The vulnerability is not recorded in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is web-based: an adversary must supply crafted input to the plugin’s data fields that is subsequently stored and rendered. Successful exploitation would allow arbitrary script execution in the browsers of users who view the affected content.
OpenCVE Enrichment
EUVD