Impact
The CMB2 WordPress plugin contains a stored cross‑site scripting flaw in the textarea_code field. The code accepts input from an unauthenticated guest, stores it without proper sanitization or escaping, and later renders it in post or page output. Thus attackers can inject arbitrary JavaScript that will execute whenever a visitor views the affected page.
Affected Systems
The vulnerability affects CMB2 versions 2.13.1 and earlier. WordPress sites that host a public CMB2 form allowing a textarea_code field are at risk. Any visitor can trigger the front‑end save because the required nonce is publicly available.
Risk and Exploitability
The CVSS base score is 7.2, indicating a high‑severity vulnerability. The exploitation probability EPSS is not available, and the vulnerability is not yet listed in the CISA KEV catalog. Because the attack vector does not require authentication and only a public nonce is needed, the likelihood of exploitation is high in practice. Attackers can inject scripts that run in the context of any user who views the compromised content, leading to defacement, credential theft or drive‑by infections.
OpenCVE Enrichment