Impact
This vulnerability is caused by improper neutralization of input during web page generation, allowing malicious scripts to be stored within a WordPress site’s content. When a visitor loads the affected content, the stored script executes in the user’s browser, potentially enabling arbitrary client‑side code execution.
Affected Systems
The issue concerns the Benjamin Intal Stackable plugin, also known as stackable‑ultimate‑gutenberg‑blocks, for all versions from its initial release up to and including 3.19.5.
Risk and Exploitability
The CVSS score of 5.9 places the risk in the medium range, while the EPSS score of less than 1% indicates a low likelihood of active exploitation currently. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves any user‑supplied input that the plugin stores and later renders, requiring an attacker to insert malicious code into a persisted block or field.
OpenCVE Enrichment