Impact
This vulnerability is a stored cross‑site scripting flaw that occurs when user‑supplied data is not properly escaped during page rendering. An attacker can inject malicious scripts that are persisted and served to any site visitor, enabling session hijacking, defacement, or drive‑by malware attacks. The weakness is identified as CWE‑79.
Affected Systems
The affected product is the DigitalCourt Boxed Content WordPress plugin version 1.0 and earlier. All installations running those versions are susceptible; later versions are not known to be affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need to inject malicious payloads through the plugin’s content entry interface; once stored, the payload executes in the browsers of all users who view the affected content.
OpenCVE Enrichment
EUVD