Impact
The flaw is an improper neutralization of input during page generation that allows stored Cross‑Site Scripting. Based on the description, it is inferred that malicious code injected by an attacker can be saved in the database and then executed when the plugin’s output is rendered to other users, potentially compromising their browsers.
Affected Systems
The vulnerability affects the Fusion Page Builder – Gallery extension produced by Agency Dominion Inc. All installed copies of the plugin with versions up through 1.7.6 are impacted, as the flaw exists from the earliest release up to that maximum version.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk profile, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The likely attack vector is the injection of malicious input into a field provided by the plugin, which is then stored and later rendered—this inference is based on the description of a stored XSS flaw.
OpenCVE Enrichment
EUVD