Impact
The Image Hover Effects Block plugin allows stored XSS because it fails to neutralize user input when rendering block content. This flaw matches the description for CWE‑79 and can enable an attacker to run arbitrary JavaScript in the browsers of any visitor who loads a page containing a malicious block. Such scripts could steal credentials, hijack sessions, or deface content.
Affected Systems
The vulnerability is present in Blocksera’s Image Hover Effects Block plugin for WordPress versions up to and including 1.4.5. Only sites that have installed this plugin within that version range are affected.
Risk and Exploitability
The CVSS base score of 6.5 denotes moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Exploitation requires that an attacker can insert malicious payload into a block via the WordPress admin or API; the payload is then stored and rendered on every page load, delivering the script to all site visitors.
OpenCVE Enrichment
EUVD