Impact
The vulnerability is an improper neutralization of input during web page generation. It allows an attacker to store malicious script code in the SKT Blocks plugin’s content fields, resulting in Stored XSS when the page is rendered. The primary impact is the ability to steal credentials, hijack user sessions, or deface site content, compromising confidentiality and integrity for site visitors.
Affected Systems
The exploitation affects the WordPress SKT Blocks plugin developed by sonalsinha21. All releases from the initial version through version 1.8 are vulnerable, meaning any site running SKT Blocks ≤ 1.8 is impacted.
Risk and Exploitability
The CVSS score of 6.5 denotes a moderate severity, while the EPSS score of less than 1 % indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the capability to add or edit block content, which may be granted to authenticated editors or admins. An attacker who can inject code via these fields can cause the stored XSS to execute in the browsers of any user who visits the affected page.
OpenCVE Enrichment
EUVD