Impact
This flaw is a DOM‑based Cross‑Site Scripting vulnerability that arises from improper neutralization of user input during page rendering in the Ultimate Blocks WordPress plugin. Because the plugin fails to sanitize or escape data it incorporates into the browser DOM, an attacker can inject arbitrary JavaScript that executes in the context of any user who visits a manipulated page, allowing theft of session cookies, redirection, or the execution of further malicious actions.
Affected Systems
All installations of the Ultimate Blocks plugin for WordPress that are version 3.2.9 or earlier. No specific sub‑versions are listed beyond the <= 3.2.9 cutoff.
Risk and Exploitability
The CVSS score of 6.5 places this vulnerability in the moderate range, and the EPSS score of less than 1% indicates that it is considered unlikely to be widely exploited in the near term. The vulnerability does not appear in the CISA KEV catalog, so no known active exploits are reported. The attack surface is client‑side; an attacker only needs to entice a victim to load a page containing crafted input, requiring no privileged access or server‑side code execution.
OpenCVE Enrichment
EUVD