Impact
The plugin contains an improper neutralization of input during web page generation, enabling a stored cross‑site scripting flaw. An attacker could inject JavaScript that executes in the context of any visitor who loads a page containing the compromised media entry. The vulnerability is documented as CWE‑79 and has a CVSS score of 6.5, indicating moderate impact on confidentiality and integrity.
Affected Systems
The flaw appears in bPlugins Video Gallery Block from the earliest available releases through version 1.1.0. WordPress sites that are running any of these plugin versions are affected, regardless of other security configurations.
Risk and Exploitability
The CVSS score of 6.5 and EPSS < 1% suggest the risk is moderate but the likelihood of a successful exploitation in the wild is low at the time of this analysis. It is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation. The attack vector is likely a stored XSS injected through the plugin’s content fields, which requires the attacker to input data that is persisted by the plugin.
OpenCVE Enrichment
EUVD