Impact
The flaw is an improper neutralization of input during web page generation, resulting in a reflected Cross‑Site Scripting vulnerability in the LambertGroup HTML5 Radio Player – WPBakery Page Builder Addon. The weakness is identified as CWE‑79 and allows an attacker to cause a victim’s browser to execute malicious script when the affected page is rendered.
Affected Systems
LambertGroup HTML5 Radio Player – WPBakery Page Builder Addon version 2.5 or earlier, used as an addon in WordPress sites
Risk and Exploitability
The CVSS score is 7.1, indicating moderate to high severity. EPSS is below 1 %, implying a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker supplying malicious input to the addon’s fields so that the script is reflected back into the page. Because the XSS is reflected, active user interaction with the rendered page is required for exploitation.
OpenCVE Enrichment
EUVD