Impact
The vulnerability is a stored cross‑site scripting flaw caused by improper neutralization of input during web page generation. An attacker can inject a malicious script that is stored by the BuddyDev Activity Plus Reloaded for BuddyPress plugin and later executed in the browsers of users who view the affected content. This can lead to credential theft, defacement, or other client‑side attacks as described by CWE‑79.
Affected Systems
BuddyDev’s Activity Plus Reloaded for BuddyPress plugin is affected for all releases from the earliest version up to and including 1.1.2. Any WordPress site running this plugin version or earlier is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of current exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote through the WordPress web interface, but this inference is based on the nature of the plugin and the description of stored XSS. An attacker would need to create or provide content that includes a malicious payload, which is then stored and served to other site visitors.
OpenCVE Enrichment