Impact
The vulnerability is an improper neutralization of input in the output rendered by the BWL Knowledge Base Manager plugin, which allows stored cross‑site scripting. An attacker can inject malicious JavaScript that is saved by the plugin and later served to visitors of the site, enabling session hijacking, credential theft, defacement or other malicious activities. The weakness is classified under CWE‑79.
Affected Systems
The affected plugin is xenioushk BWL Knowledge Base Manager for WordPress. All installations running version 1.6.3 or earlier are vulnerable; the list of lower bounds is not specified beyond "n/a through <= 1.6.3."
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score shows a probability of exploitation of less than 1%, suggesting that while the flaw is present, the likelihood of an attack is currently low, and the vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an attacker who can submit content that the plugin stores and later triggers any visitor to the affected page to execute the stored script.
OpenCVE Enrichment