Impact
Improper neutralization of input during web page generation leads to DOM‑based cross‑site scripting. An attacker could inject and execute arbitrary JavaScript in the victim’s browser when a vulnerable page is loaded.
Affected Systems
The issue affects the WordPress Fusion Builder plugin from its earliest versions up through 3.13.2, distributed by ThemeFusion. Users running any of those versions within a WordPress installation are susceptible; no additional platform details or CPE strings are provided in the description.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of <1% indicates a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. No additional details about exploitation path are provided in the CVE description.
OpenCVE Enrichment