Impact
The Flex Guten WordPress plugin is vulnerable to a stored Cross‑Site Scripting flaw caused by insufficient sanitization of the thumbnailHoverEffect parameter. The vulnerability allows an authenticated attacker with Contributor authority or higher to inject arbitrary scripts that execute when a user views a page containing the injected content. This weakness is classified as CWE‑79.
Affected Systems
The flaw affects the Flex Guten – Multile Blocks plugin from dragwp in all versions up to and including 1.2.5. Users running any of these releases and granting Contributor‑level access to others are at risk.
Risk and Exploitability
The severity is moderate with a CVSS score of 6.4, and the EPSS score is less than 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated Contributor‑level access, so it is a local threat rather than remote unauthenticated.
OpenCVE Enrichment
EUVD