Impact
An improper neutralization of input during web page generation allows an attacker to inject malicious scripts into a web page displayed to other users. The flaw is a DOM‑based cross‑site scripting vulnerability triggered when the BBCode Deluxe plugin processes user‑supplied BBCode without proper escaping. Successful exploitation can lead to theft of session cookies, defacement of content, or execution of arbitrary JavaScript in the victim’s browser, as defined by CWE‑79.
Affected Systems
The issue impacts the DevynCJohnson BBCode Deluxe WordPress plugin for all versions up through 2020.08.01.2. Any site that has installed any release equal to or older than this date is vulnerable, regardless of site ownership or permission levels, because the plugin fails to sanitize unsafe BBCode before rendering.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity while the EPSS score of < 1% reflects a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely DOM‑based, allowing unauthenticated visitors to trigger the flaw and inject code directly into the browser context once the plugin processes unescaped input.
OpenCVE Enrichment
EUVD