Impact
The WP Hello Bar plugin allows authenticated users with administrator privileges to insert arbitrary scripts via the 'digit_one' and 'digit_two' input parameters. Because the plugin does not sanitize or escape these fields upon output, the injected scripts become stored XSS payloads that execute whenever any user loads a page containing the affected data. This flaw enables attackers to compromise the browsers of site visitors and potentially steal credentials or perform other malicious actions.
Affected Systems
The vulnerability affects any WordPress installation running the WP Hello Bar plugin up to and including version 1.02, distributed by Norcross. Sites that have installed this version, either directly from the WordPress plugin repository or via the provided zip archive, are susceptible. All users of such installations are potentially exposed if the plugin’s forms are used.
Risk and Exploitability
The CVSS score is 4.4, indicating moderate severity, and the EPSS score is below 1 %, suggesting a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers must possess administrator-level access to the WordPress site to inject the malicious payload, but once injected the script runs in any visitor’s browser regardless of authentication. The combination of limited privilege requirements and the ability to persistently affect users raises the overall risk level for environments running the affected plugin version.
OpenCVE Enrichment