Impact
The IndieBlocks WordPress plugin is vulnerable to a stored cross‑site scripting flaw that allows an authenticated user with Contributor or higher privileges to insert malicious JavaScript via the kind parameter; the payload is saved and executed whenever any page containing the injected content is viewed.
Affected Systems
WordPress sites using the IndieBlocks plugin from janboddez, versions up to and including 0.13.2 are affected. The vulnerability exists in every release within that range regardless of additional configuration.
Risk and Exploitability
The flaw has a CVSS score of 6.4, indicating moderate severity, and an EPSS below 1%, suggesting exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. It is exploitable only by users who have authenticated access with Contributor or higher role, and the malicious code will run in the context of any visitor to the impacted page.
OpenCVE Enrichment
EUVD