Impact
The Tribal plugin contains a stored cross‑site scripting flaw that allows an attacker to input data that is not properly sanitized before being rendered in a web page. This vulnerability can cause malicious scripts to run in the browsers of anyone who views the affected content, potentially allowing the attacker to perform arbitrary client‑side actions.
Affected Systems
WordPress sites that have the Tribal plugin from thetechtribe installed in any version up to and including 1.3.3 are affected.
Risk and Exploitability
The CVSS base score is 5.9, indicating moderate severity, and the EPSS score is less than 1 %, meaning the likelihood of public exploitation is very low at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an adversary must be able to add or modify content through the plugin’s interface or other accessible input mechanisms so that the unsanitized data becomes stored and subsequently displayed to site visitors. Based on the description, it is inferred that an attacker with sufficient user privileges or who can influence stored data would be able to trigger this flaw.
OpenCVE Enrichment
EUVD