Impact
The WordPress wBounce plugin for kevinweber contains an Improper Neutralization of Input During Web Page Generation vulnerability that allows attackers to store malicious JavaScript. When a victim views an affected page, the injected code runs in the victim’s browser, potentially enabling session hijacking, defacement, or theft of sensitive data. This weakness is a classic stored XSS (CWE‑79).
Affected Systems
All installations of the wBounce plugin by kevinweber with version 1.8.1 or older are affected. The CVE data does not reference any fix beyond version 1.8.1, so versions newer than 1.8.1 have not been proven to be free of this flaw.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating medium severity. The EPSS score is below 1 %, suggesting a low likelihood of known exploitation, and the issue is not listed in the CISA KEV catalog. An attacker would need to submit malicious input through the plugin’s interface; the script is then stored and rendered to all future visitors on the affected page.
OpenCVE Enrichment
EUVD