Impact
The vulnerability is an improper neutralisation of script‑related HTML tags in Cozy Blocks, enabling attackers to inject arbitrary code into a page via the plugin’s content handling. This results in a basic cross‑site scripting (XSS) flaw that can compromise the confidentiality and integrity of user sessions, potentially leaking session cookies or executing phishing attacks. The weakness is identified as CWE‑80.
Affected Systems
The issue affects Cozy Themes Cozy Blocks (the Cozy‑Addons plugin) from the earliest available version through every release up to and including version 2.1.29. Any WordPress site that has installed an affected revision of the plugin, regardless of domain or user role, is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score below 1% suggests a low likelihood of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers likely gain influence by submitting crafted content through the plugin’s user interface, thereby injecting malicious script that would execute in the browser of any visitor who loads the affected page. Because the flaw resides in content sanitisation, a successful exploit requires the attacker to have permissions to add or edit content via the plugin.
OpenCVE Enrichment
EUVD