Impact
This flaw is an Improper Neutralization of Input During Web Page Generation that allows DOM‑based XSS in the WPWheels BlockWheels plugin. When a victim’s browser processes a page generated by the plugin, unescaped data is injected directly into the DOM, enabling an attacker to run arbitrary JavaScript in the user’s context. Such code can steal session cookies, deface the site, or perform other malicious actions within the scope of the site’s privileges.
Affected Systems
WordPress sites that have installed the BlockWheels plugin version 1.0.2 or earlier are affected. All installations of this plugin, regardless of hosting environment, fall within the vulnerable range, as the issue is present from the first release through 1.0.2.
Risk and Exploitability
The CVSS score of 6.5 rates the vulnerability as moderate severity. An EPSS score below 1% indicates a very low current exploitation probability, and the issue is not listed in the CISA KEV catalog. Attackers can exploit the vector by crafting a URL or manipulating an input field that the plugin reflects into the page, requiring only that a user visit the malicious link in a web browser. No elevated privileges or system access are necessary for exploitation.
OpenCVE Enrichment
EUVD