Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during web page generation. An attacker who can deposit malicious content through the plugin can cause arbitrary JavaScript to execute in the browsers of anyone who views the affected page, potentially compromising user data and the integrity of the site. The impact is the ability to run client‑side code in the victim’s environment.
Affected Systems
Stiofan BlockStrap Page Builder - Bootstrap Blocks plugin, any version from the first release through and including 0.1.36.
Risk and Exploitability
Based on the description, it is inferred that attackers might need to submit malicious content through the plugin’s interface, which could require some level of authentication or privileged access. The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score is less than 1 %, indicating a very low current exploitation probability, and the issue is not listed in CISA KEV. No confirmed public exploits are known, but if the attacker can inject data, stored XSS enables arbitrary JavaScript execution in a victim’s browser.
OpenCVE Enrichment
EUVD