Impact
The vulnerability in the BP Messages Tool is a reflected XSS flaw caused by insufficient input sanitization. When a malicious URL or input is supplied to the plugin, the data is echoed back into the HTML response without proper encoding, allowing an attacker to run arbitrary JavaScript in the victim’s browser. This could enable session hijacking, credential theft, or defacement of the site’s content.
Affected Systems
The BP Messages Tool plugin developed by shanebp, in all releases up to and including version 2.2, is affected. WordPress sites that have installed this plugin without updating past 2.2 are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity vulnerability. The EPSS score of less than 1% shows a very low probability of exploitation at the time of this analysis, and the flaw is not listed in CISA KEV. The attack most likely occurs through a crafted URL or input field exposed by the plugin, requiring the victim to click or visit the malicious link. If successful, the attacker can execute client‑side code in the context of the site.
OpenCVE Enrichment
EUVD