Impact
The vulnerability is an improper neutralization of input that allows stored XSS. An attacker can inject malicious scripts into the plugin’s input fields, and those scripts are stored and later rendered as part of the web page. When a user views the affected page, the injected script executes in the user’s browser, giving the attacker the ability to run arbitrary JavaScript within that context.
Affected Systems
Vimal Kava AI Search Bar open‑ai‑search‑bar is affected for all released revisions up to and including version 2.1. The plugin is a WordPress add‑on that installs under the AI Search Bar namespace.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score of <1% signals a very low probability of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves user input into the search bar, which the plugin stores and later displays without proper output encoding. Because the flaw is stored, a single compromised input can affect all users who view the affected page.
OpenCVE Enrichment
EUVD