Impact
Unauthenticated Cross Site Scripting (XSS) exists in the WordPress Parallax Section Block plugin versions 2.0.4 and earlier. The flaw arises when the plugin fails to properly sanitize user‑supplied input that is rendered in the page. As a result, an attacker can inject arbitrary scripts that execute in the browsers of visitors who view affected content, potentially leading to session hijacking, credential theft, or defacement. The vulnerability is a classic example of CWE‑79, implying both confidentiality and integrity risks if exploited.
Affected Systems
Affected systems are WordPress sites that have the bPlugins Parallax Section Block plugin installed at any version up to and including 2.0.4. No other WordPress components or plugins are explicitly listed as vulnerable. Site owners should verify the installed version of this plugin and apply the recommended update.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, and the flaw is exploitable without authentication, making the risk substantial. EPSS data is not available, and the vulnerability has not been listed in the CISA KEV catalog, suggesting no known large‑scale exploitation at this time. However, the lack of required credentials and the native cross‑site execution path make it a prime target for automated attacks, warranting immediate attention.
OpenCVE Enrichment