Impact
A stored cross‑site scripting (XSS) vulnerability exists in the Brainstorm Force Starter Templates WordPress plugin, allowing an attacker to inject malicious scripts that will be rendered when the web page is loaded. The flaw arises from improper neutralization of user input during web page generation, which is identified as CWE‑79. Successful exploitation could let an attacker run arbitrary JavaScript in the context of site visitors. Based on the description, it is inferred that such exploitation could compromise user sessions or deface content.
Affected Systems
The vulnerability applies to all versions of the Starter Templates plugin up to and including version 4.7.7 released by Brainstorm Force. Users who have not upgraded past this point remain exposed.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as medium severity, and the exploit probability score (EPSS) is not available, indicating that no public exploitation data is known at this time. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is web‑based and requires the attacker to insert malicious input that is stored by the plugin’s settings or content creator interface. An attacker with access to such input can later cause victim browsers to execute the injected script when the page is rendered.
OpenCVE Enrichment