Impact
The vulnerability is an Improper Neutralization of Input during Web Page Generation, manifesting as a DOM‑Based Cross‑Site Scripting flaw. An attacker can inject malicious script into the browser context of an affected user, potentially allowing session hijacking, defacement, or the execution of arbitrary client‑side code. The impact is limited to the browser of the victim but can affect many users if the injected script propagates or performs social‑engineering attacks.
Affected Systems
The flaw affects the WordPress plugin Chamber Dashboard Business Directory by Morgan Kay on all versions from the earliest release up to and including 3.3.11. Users running any of these versions are susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate‑to‑high potential for exploitation, while the EPSS score of less than 1% suggests a low probability of a real‑world attack at present. The vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attack vector requires an attacker to supply a malicious URL or input that is rendered on the page, thus exploiting the DOM rendering logic. No special privileges are needed beyond normal user access.
OpenCVE Enrichment
EUVD