Impact
The Breeze Display WordPress plugin has a stored XSS vulnerability in the cal_size parameter that allows an authenticated attacker with contributor level or higher to inject script tags that will be served to all users who view the affected page. The flaw stems from insufficient input validation and missing output escaping.
Affected Systems
Any WordPress site using Breeze Display plugin version 1.2.3 or earlier is at risk. The vulnerability affects the plugin’s shortcode implementation available to users with contributor role or higher.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate risk. The EPSS score of less than 1% suggests low exploitation likelihood and the vulnerability is not listed in CISA KEV. Exploitation involves submitting a malicious cal_size value via the shortcode editor; the script is stored and executed whenever any visitor loads the content page.
OpenCVE Enrichment
EUVD