Impact
This vulnerability is a DOM‑based XSS flaw in the SKT Skill Bar WordPress plugin. Improper neutralization of user input allows attacker‑crafted data to be rendered unescaped in the browser, leading to arbitrary JavaScript execution within the context of any visitor who views a page that includes the plugin.
Affected Systems
The issue affects the SKT Skill Bar plugin by sonalsinha21, versions 2.5 and earlier. Any WordPress installation that has the plugin at or below the 2.5 release is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 shows a medium severity level, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Attackers can trigger the vulnerability by submitting or embedding malicious input that is later reflected by the plugin without appropriate sanitization; based on the description, it is inferred that no authentication or privileged access is required.
OpenCVE Enrichment