Impact
The vulnerability is a stored cross‑site scripting flaw that permits an attacker to inject malicious JavaScript into the BuddyPress Members Only plugin. When a crafted input reaches the plugin’s output path, the injected code is rendered by browsers of any visitors to the affected pages. This can enable session hijacking, cookie theft, defacement, or redirection of users to malicious sites.
Affected Systems
The issue affects Tomas BuddyPress Members Only, a WordPress plugin used for managing member visibility. All releases up to and including version 3.5.3 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers would likely exploit the vulnerability by submitting unsanitized input through plugin fields that are then served unescaped to other users. If successful, the impact could be widespread across all users who view the compromised content.
OpenCVE Enrichment
EUVD