Impact
LambertGroup’s Multimedia Playlist Slider Addon for WPBakery Page Builder contains an improper neutralization of input during web page generation, allowing a reflected XSS flaw. An attacker can embed malicious JavaScript in a crafted URL, which is executed in the context of the site when a user visits that URL. This can lead to theft of session cookies, defacement, or other client‑side attacks.
Affected Systems
The vulnerability affects all releases of the Multimedia Playlist Slider Addon for WPBakery Page Builder up to and including version 2.1. Any site running this plugin within that range is potentially exploitable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity, while the EPSS score of less than 1 % suggests that exploitation attempts are currently rare, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a reflected XSS, requiring a victim to click a malicious link; therefore the risk is limited to user‑interactive scenarios but remains significant for sites that rely on the plugin for media presentation.
OpenCVE Enrichment
EUVD