Impact
An attacker can supply unsanitized data that is incorporated into the C9 Blocks plugin output, creating a DOM‑based XSS condition. This allows the injection of arbitrary JavaScript into pages rendered by the victim’s browser, enabling session hijacking, cookie theft, phishing, or defacement of the site. The weakness is identified as CWE‑79 – Improper Neutralization of Input. Because the flaw requires the input to reach the web page generation code, it is considered a moderate‑severity exploitation scenario.
Affected Systems
The vulnerability affects the WordPress C9 Blocks plugin by covertnine, specifically all releases from the initial version through version 1.7.7 inclusive. Later releases are not affected.
Risk and Exploitability
With a CVSS score of 6.5 the issue is rated moderate. The EPSS score of less than 1 % indicates a low probability of exploitation, and it is not listed in the CISA KEV catalog. Likely exploitation requires a user or administrator to submit content via the plugin that contains the malicious payload, after which any visitor who views the affected page will execute the code in their browser.
OpenCVE Enrichment
EUVD