Impact
The CubeWP Framework plugin for WordPress contains a DOM‑Based Cross‑Site Scripting flaw that fails to neutralize user input before it is rendered in the browser.
Affected Systems
This issue affects all installations of the Imran Tauqeer CubeWP plugin with versions up to and including 1.1.23; no later versions are known to be vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity while the EPSS score of less than 1% suggests a very low likelihood of exploitation at present and the vulnerability is not listed in the CISA KEV catalog. Potential attackers could craft malicious URLs or form inputs that, when processed by the plugin, execute arbitrary JavaScript in the victim’s browser, enabling session hijacking, defacement or cookie theft. The attack requires an infected user to visit a malicious link or enter tainted data, so it relies on social engineering rather than direct network exploitation.
OpenCVE Enrichment
EUVD