Impact
The Knowledge Base plugin for WordPress is vulnerable to stored cross‑site scripting because user‑supplied attributes in the "kbalert" shortcode are not properly sanitized or escaped. An attacker with contributor privileges can embed arbitrary JavaScript that will run whenever a user views a page containing the injected shortcode. This flaw may lead to session hijacking, defacement, or theft of sensitive information from site visitors, compromising confidentiality and integrity.
Affected Systems
All instances of the Knowledge Base WordPress plugin with versions 2.3.0 or earlier are susceptible. The vulnerability exists across all WordPress installations that have installed any of these affected versions of the plugin, regardless of other configuration settings.
Risk and Exploitability
The flaw has a CVSS score of 6.4, indicating moderate severity. Because the EPSS score is reported as less than 1%, the likelihood of exploitation is considered low at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector requires an authenticated user with contributor-level access or higher, who can inject malicious code via the kbalert shortcode. Once injected, the script executes automatically for any visitor to the affected page, making it a significant risk for sites with larger user bases or high traffic.
OpenCVE Enrichment
EUVD