Impact
The Blox Lite plugin stores user input without proper neutralization, creating a stored cross‑site scripting flaw. An attacker can embed malicious JavaScript that will later execute in any victim’s browser when the stored data is rendered. This could allow cookie theft, session hijack, defacement, or execution of arbitrary code within the context of the author’s permissions. The weakness is catalogued as CWE-79.
Affected Systems
WordPress users running Nick Diego’s Blox Lite plugin version 1.2.8 or earlier are affected. The vulnerability applies to all product releases up to and including 1.2.8, regardless of the WordPress version installed. Users must verify which plugin revision they have and upgrade if a later release has been issued.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact. The EPSS score of less than 1% signals a very low probability of exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. However, because the flaw is stored, merely submitting malicious content via the plugin’s input fields can expose all visitors who load the affected page. The likely attack vector is a web‑based injection through any form or content entry point that the plugin processes.
OpenCVE Enrichment