Impact
The BRW plugin contains an improper input neutralization flaw that permits stored cross‑site scripting. A malicious actor can inject JavaScript via data stored in the plugin, which will be rendered to other site visitors. The resulting impact is the ability to hijack user sessions, deface content, or perform click‑jacking attacks. This weakness is mapped to CWE‑79.
Affected Systems
The vulnerability affects ovatheme BRW version 1.8.6 and earlier. Any WordPress site using the BRW plugin within this version range is potentially exposed until the plugin is updated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. EPSS <1% suggests the likelihood of exploitation is low, and it is not listed in KEV. The attack vector is likely through administration of the plugin where malicious input can be stored; normal visitors are not required to execute the vulnerability. Because the flaw requires interacting with plugin settings, having administrative access is a prerequisite, which restricts the attack surface.
OpenCVE Enrichment
EUVD