Impact
The plugin contains insufficient input sanitization and output escaping around the user's display name and reply content, allowing an authenticated user with subscriber level or higher to store malicious scripts that are rendered when another user views a page. The malicious scripts are executed as arbitrary JavaScript within the victim's browser session.
Affected Systems
robin-w's bbp style pack plugin for WordPress, versions up to and including 6.4.8, is affected. Any WordPress installation that has installed the plugin at these versions and grants subscriber‑level access to users is vulnerable.
Risk and Exploitability
The CVSS score is 6.4, indicating a moderate to high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. Because exploitation requires the attacker to create a reply wrapped in a <pre> tag, the attack vector is authenticated via subscriber‑level actions. The vulnerability can be leveraged after gaining authenticated access sufficient to edit profile display names and submit replies, which is commonly possible for a wide range of users on typical WordPress sites.
OpenCVE Enrichment