Impact
The bPlugins Team Section Block plugin (versions up through 1.0.9) contains an Improper Neutralization of Input During Web Page Generation vulnerability that can be exploited for stored cross‑site scripting. An attacker can inject malicious JavaScript that is then rendered by the browser for any user who views the affected page. This can lead to defacement, credential theft, or the execution of tab‑nabbing attacks on site visitors.
Affected Systems
WordPress websites running the bPlugins Team Section Block plugin version 1.0.9 or earlier are impacted. The problem does not affect versions newer than 1.0.9, as those releases incorporate the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s content entry fields, where a malicious user can store a script that is later served to all site visitors. Should an attacker succeed, they could gain unauthorized access to user session information or manipulate the page content for phishing or malware delivery.
OpenCVE Enrichment
EUVD