Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw that arises from improper neutralization of user input during web page generation. It enables an attacker to embed malicious scripts that execute in the browser of anyone who visits a page generated by the plugin. Because the payload runs in the context of the website, an attacker could steal user credentials, deface the site, or perform further phishing or malware distribution actions. The weakness is identified as a CWE‑79 input validation flaw.
Affected Systems
The SpaBiz plugin for WordPress, developed by burgersoftware, is affected. Any installation of version 1.0.18 or earlier is vulnerable; versions newer than 1.0.18 are not impacted.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as a moderate‑severity issue. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would typically involve an attacker crafting a malicious URL or form input that the plugin fails to sanitize, causing the victim’s browser to execute attacker‑supplied code. The attack vector is client‑side, requiring only that a victim view a crafted page.
OpenCVE Enrichment
EUVD