Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw in the CyberChimps Responsive Blocks plugin for WordPress. It occurs because the plugin does not properly neutralize user‑supplied input before rendering it in the browser, allowing an attacker to inject arbitrary JavaScript that will execute in the context of any visitor who views a page containing the malicious data.
Affected Systems
WordPress sites that have installed CyberChimps Responsive Blocks (responsive‑block‑editor‑addons) version 2.0.6 or earlier are affected. The issue applies whenever the plugin is active and processes user input that is rendered in the browser.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score is below 1%, signifying a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Because the flaw is client‑side, an attacker would need to provide a crafted page or data that users subsequently load. The risk level is moderate for sites with a wide visitor base or that expose block configuration data to untrusted input.
OpenCVE Enrichment
EUVD