Impact
The vulnerability is an instance of Improper Neutralization of Input During Web Page Generation, allowing an attacker to store malicious script code in the Visual Composer Website Builder plugin’s data structures. When a user accesses a page generated by the plugin, the injected code is rendered in their browser, enabling arbitrary script execution.
Affected Systems
The flaw affects the Visual Composer Website Builder plugin for WordPress, specifically all installations from the earliest release through version 45.11.0. Any WordPress site running this plugin version or older is potentially exposed.
Risk and Exploitability
The base score is 6.5 on the CVSS scale, reflecting a moderate risk. The EPSS score of less than 1% indicates that the likelihood of public exploitation is low and no exploit evidence is provided in the CVE data. The vulnerability is not listed in CISA’s KEV catalog. The most probable attack vector is an attacker or a compromised user submitting malicious content through the plugin’s interface, which is then stored and later rendered to all visitors.
OpenCVE Enrichment
EUVD