Impact
The vulnerability is a Stored Cross‑Site Scripting flaw that results from the CyrilG Fyrebox Quizzes plugin failing to properly neutralize user input when generating web pages. An attacker who can insert content into the plugin’s data fields can store malicious scripts that will execute in the browsers of any visitor who loads a page rendered by the plugin.
Affected Systems
The flaw affects the CyrilG Fyrebox Quizzes WordPress plugin version 3.1 and earlier. Users with any of these versions installed on a WordPress site are vulnerable until a later, patched release is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates medium impact, while the EPSS score of less than 1% suggests that the probability of exploitation is currently very low. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through the plugin’s data entry interface, where an attacker can inject a script that is stored in the database and served to all site visitors.
OpenCVE Enrichment
EUVD