Impact
Boot Div WP Sitemap contains an XSS flaw that lets an attacker insert malicious JavaScript which is stored and then served with normal web pages. This issue is a stored Cross‑Site Scripting vulnerability as described in the CVE payload.
Affected Systems
Any WordPress installation using Boot Div WP Sitemap version 1.0.0 or earlier. The plugin is distributed under the Boot Div:WP Sitemap category.
Risk and Exploitability
The CVSS score of 6.5 places it in a medium severity range. The EPSS score is below 1%, indicating very low likelihood of exploitation at this time, and it is not listed in KEV. Attackers would reach the exposed input points in the plugin’s interface; however, the description does not specify whether authentication is required, so the exact attack vector is inferred rather than stated.
OpenCVE Enrichment
EUVD