Impact
The vulnerability is a DOM‑based XSS caused by failure to neutralize input during page generation, allowing arbitrary script execution in the user’s browser. It falls under CWE‑79.
Affected Systems
Affected installations are those running the voidcoders WPBakery Visual Composer WHMCS Elements plugin version 1.0.4.3 or older. The issue applies from the plugin’s initial release through 1.0.4.3.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely a DOM‑based cross‑site scripting attack that occurs when user input is processed during web page generation and subsequently executed by the browser.
OpenCVE Enrichment