Impact
The vulnerability is a cross‑site scripting flaw in the WPMU DEV Branda White Labeling plugin versions up to 3.4.32. It is caused by improper sanitization of subscriber‑related input that the plugin outputs in the page. As a result, a malicious actor can embed arbitrary JavaScript that is executed in the context of any user who views the affected page, potentially exposing sensitive information or modifying the user experience. This flaw aligns with CWE‑79.
Affected Systems
Any WordPress installation that has the WPMU DEV Branda White Labeling plugin installed and running in a version 3.4.32 or earlier is affected. The flaw is present regardless of the WordPress site's configuration and affects the default subscriber role or any role that can view subscriber data rendered by the plugin.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high‑severity vulnerability. Exploitation requires an attacker to supply crafted input that the plugin fails to escape. Because the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, there is no evidence of a widely used exploit, but the high severity suggests that organizations should evaluate the risk. The likely attack vector is user‑controlled input that reaches the plugin’s rendering logic and is not sanitized before being sent to the browser.
OpenCVE Enrichment