Impact
The Brandfolder WordPress plugin is vulnerable to stored cross‑site scripting through the ‘id’ parameter in all releases up to 5.0.19. An authenticated user with Contributor or higher privileges can inject arbitrary JavaScript that is persisted and executed whenever a page containing the injected payload is viewed by any user.
Affected Systems
WordPress sites using the Brandfolder plugin, versions 5.0.19 and earlier.
Risk and Exploitability
The vendor scores the vulnerability with a CVSS of 6.4, indicating moderate severity. The EPSS of less than 1 % suggests the current exploitation probability is low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated Contributor‑level account, and the attacker can inject scripts via the id parameter that persist until removed, thereby targeting other users who visit the affected pages.
OpenCVE Enrichment
EUVD