Impact
The Theme Blvd Sliders plugin for WordPress includes a flaw where user input is not properly neutralized during page rendering, exposing a reflected Cross‑Site Scripting vulnerability classified as CWE‑79. This flaw lets an attacker inject and execute arbitrary JavaScript in a victim’s browser when the victim views the crafted page, potentially leading to session hijacking, credential theft, or defacement of the site.
Affected Systems
Affected products include the Theme Blvd Sliders plugin developed by Jason. All releases from the earliest published version up to and including version 1.2.5 are impacted. No posts indicate that later releases have incorporated the necessary fix.
Risk and Exploitability
The flaw carries a CVSS score of 7.1, signalling a high severity threat. However, the EPSS score is below 1 %, suggesting that real‑world exploitation likelihood is low. The vulnerability is currently not listed in the CISA KEV catalog. Inferred attack scenarios involve an attacker crafting URLs or form submissions that inject malicious script into a page that a victim then loads; the attacker requires no prior authentication to execute the script in the victim’s context, but the attack relies on user interaction to load the malicious content.
OpenCVE Enrichment
EUVD