Impact
The CVE involves a stored cross‑site scripting flaw in the Cision Block WordPress plugin. An authenticated contributor or higher user can submit a payload via the id parameter, which is not properly sanitized or escaped before being stored. The injected script will execute for any user who then views the affected page, enabling theft of session cookies, defacement, or malicious redirects. This violates confidentiality and integrity and can be leveraged to compromise the entire site for every visitor.
Affected Systems
WordPress sites that have the Cision Block plugin installed, specifically versions 4.3.0 or earlier. Any site using these older releases exposes the client‑side rendering of the id parameter without proper sanitization, regardless of the WordPress version.
Risk and Exploitability
CVSS base score of 6.4 indicates a medium risk. The EPSS score is below 1% showing a low public exploitation likelihood at this time. The vulnerability is not listed in the CISA KEV catalog. The attack requires authenticated access at the Contributor level or higher, so it is not exploitable by unauthenticated users. An attacker could place malicious JavaScript that runs when any visitor loads the injected page, allowing credential theft or site compromise as described.
OpenCVE Enrichment
EUVD