Impact
This vulnerability allows attackers to store malicious script code through user input that is later rendered by the Back to Top Button plugin. Because the input is not properly escaped, an attacker can embed arbitrary JavaScript or HTML that will execute in the browser of any user viewing the affected page. The impact ranges from defacement to theft of session cookies and other sensitive information, compromising user confidentiality, integrity, and availability for browsers accessing the site.
Affected Systems
The affected product is the WordPress Back to Top Button plugin developed by Out the Box: Beam me up Scotty, version 1.0.23 and earlier. No other vendors or product versions are listed.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate risk, but the EPSS score of less than 1% shows that actual exploitation likelihood is very low. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be via the web interface that accepts user‑supplied content, usually within the plugin's configuration or content fields. An attacker would need sufficient privileges to input malicious content, which could be done by an administrator or a user with write access to plugin settings.
OpenCVE Enrichment
EUVD