Impact
The vulnerability resides in the BlockSpare plugin’s Image Carousel and Image Slider widgets, where stored HTML attributes are not properly sanitized or escaped. This flaw can be exploited to inject arbitrary JavaScript code that is persisted in the database and executed whenever a page containing the widget is loaded. The weakness aligns with CWE‑79, leading to malicious script execution in the browsers of any user who views the affected content.
Affected Systems
WordPress sites running the BlockSpare "Gutenberg Blocks & Patterns for Blogs, Magazines, Business Sites" plugin versions up to and including 3.2.13.1 are affected. The plugin is available from BlockSpare and is installed in the WordPress plugin directory.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as a medium severity issue. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and it is not currently listed in the CISA KEV catalog. The vulnerability can be leveraged by attackers who possess authenticated Contributor or higher access, allowing them to embed malicious scripts into the carousel or slider widgets. Once stored, the scripts execute in the browsers of any user who loads the compromised page, potentially leading to data theft or session hijacking.
OpenCVE Enrichment
EUVD