Impact
The Vayu Blocks plugin for WordPress allows a stored cross‑site scripting flaw via the containerWidth parameter. The flaw occurs because the option panel callback lacks a capability check and the parameter is not properly sanitized or escaped. Attackers who can authenticate as a Subscriber or higher can inject malicious JavaScript that will run every time a user visits an affected page. Based on the description, it is inferred that the injected scripts could be used to deface content, steal session cookies, or execute other malicious actions in the context of the site visitor.
Affected Systems
Themehunk’s Vayu Blocks – Website Builder for the Block Editor is affected in all releases up to and including version 1.3.1. No other versions were mentioned by the CNA. The plugin runs in WordPress sites that have been installed with those versions.
Risk and Exploitability
The CVSS base score of 6.4 signals moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The vulnerability is not in the CISA KEV catalog. Exploitation requires only authenticated access with Subscriber privileges on a WordPress instance; an attacker would use the plugin’s option panel to submit a containerWidth value that includes malicious code. Once stored, the code executes in the browser context of any visitor who loads the modified block, making it a serious threat to confidentiality, integrity, and availability of the site’s users.
OpenCVE Enrichment
EUVD