Impact
Improper neutralization of input during web page generation in Guaven Labs SQL Chart Builder results in a DOM‑based XSS flaw. The plugin renders user‑supplied data without sanitizing it, allowing the injection of scripts that would execute in the victim's browser. All released versions up to and including 2.3.7.2 are affected.
Affected Systems
The vulnerability affects the Guaven Labs SQL Chart Builder plugin for WordPress. All released versions up through and including 2.3.7.2 are susceptible; any installation of the plugin before a fix is applied is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, and the EPSS score of <1% suggests low likelihood of exploitation. The flaw is client‑side, inferred from its DOM-based nature. Exploitation requires a victim to visit a crafted page. The vulnerability is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
EUVD