Impact
Improper neutralization of user input during web page generation allows an attacker to inject malicious scripts that are executed in the context of a victim’s browser. The weakness is a DOM‑based XSS, a type of client‑side injection (CWE‑79). An attacker who succeeds could steal session cookies, deface content, or perform actions on behalf of the victim without requiring authentication.
Affected Systems
WordPress installations running the Buying Buddy IDX CRM plugin version 2.3.0 or earlier are vulnerable. Sites that have not yet applied the latest release of the plugin should be considered at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests that the likelihood of exploitation is low at present. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit is reported. The likely attack vector is a user visiting a crafted URL or interacting with a manipulated page element that the plugin renders without proper encoding.
OpenCVE Enrichment
EUVD