Impact
The vulnerability originates from improper neutralization of user‑supplied input during web page generation. As a result, an attacker can inject malicious scripts that the browser will execute in the victim’s session, leading to potential defacement, credential theft or session hijacking. The weakness corresponds to CWE‑79, a classic input validation flaw that compromises the confidentiality, integrity and availability of the affected system.
Affected Systems
LambertGroup Multimedia Playlist Slider Addon for WPBakery Page Builder is vulnerable in all releases from its initial release through version 2.1. Any WordPress site that has this plugin installed and enabled, regardless of the host environment, is at risk unless the plugin is upgraded beyond version 2.1.
Risk and Exploitability
The CVSS score of 7.1 indicates significant severity, while the EPSS score of less than 1% suggests that exploitation attempts are uncommon at present. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector would involve a crafted URL or input parameter that a victim clicks or submits, which then reflects malicious script code back to the browser. No authentication or privileged access is required, making the risk profile wide and largely exploitable via phishing or compromised content.
OpenCVE Enrichment
EUVD