Impact
The bdthemes ZoloBlocks WordPress plugin contains a DOM‑based Cross‑Site Scripting flaw that permits attackers to inject malicious JavaScript into pages generated by the plugin. When a victim visits a page that contains the unneutralized input, the script executes in the victim’s browser, allowing the attacker to steal session cookies, deface content, or execute other client‑side attacks. The weakness is categorized as CWE‑79 and undermines user confidentiality and integrity when interacting with the affected site.
Affected Systems
All WordPress installations that have the bdthemes ZoloBlocks plugin installed in any release from the earliest available versions through version 2.3.12 are vulnerable. Any site that has not upgraded past 2.3.12 and continues to use the plugin is at risk; no additional version specificity is indicated beyond the upper bound.
Risk and Exploitability
The CVSS score of 6.5 marks this vulnerability as moderate severity, and an EPSS score of less than 1% signals low likelihood of exploitation in the wild. The likely attack vector is the injection of crafted input that is reflected in the document element objects (DOM); an attacker would need to persuade a user to visit the maliciously constructed URL or submit privileged input that is eventually handled by ZoloBlocks. The vulnerability is not listed in the CISA KEV catalog, indicating no current evidence of widespread exploitation, but a vulnerable site remains susceptible to client‑side attacks if a user accesses the affected content.
OpenCVE Enrichment
EUVD