Impact
The vulnerability is a stored cross‑site scripting flaw in the codetoolbox My Bootstrap Menu plugin, allowing malicious input to be appended to stored data and later rendered as script on pages viewed by other users. A successful exploit can lead to session hijacking, credential theft, defacement or broader malicious activity via the injected scripts. The weakness falls under CWE‑79.
Affected Systems
The My Bootstrap Menu plugin versions up to and including 1.2.1 are affected. Any WordPress site running this plugin prior to a newer release is at risk; versions above 1.2.1 are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity and the EPSS score of less than 1% suggests a very low exploitation probability at present. The vulnerability is not included in the CISA KEV catalog. Likely attack vector involves submitting malicious payloads through the plugin’s editable text fields, which are then stored and subsequently served to other visitors. Successful exploitation would allow persistence via stored script code on the site.
OpenCVE Enrichment
EUVD