Impact
The burgersoftware StoreBiz plugin contains a DOM‑based cross‑site scripting flaw caused by improper neutralization of input. The vulnerability allows an attacker to inject arbitrary JavaScript that runs in the victim’s browser when a vulnerable page is accessed. No specific downstream effects such as cookie theft are asserted in the official description.
Affected Systems
WordPress sites running burgersoftware StoreBiz plugin versions up to and including 1.0.32 are affected. All releases prior to 1.0.33 contain the flaw; later versions are presumed fixed based on the vendor’s statement.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium level of severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this assessment. This vulnerability is not listed in the CISA KEV catalog. The attack vector is likely to be public and broadly exploitable, inferred because the flaw is DOM‑based XSS and no authentication is required for the page to be rendered.
OpenCVE Enrichment
EUVD