Impact
The vulnerability arises from improper neutralization of user input when rendering web pages, allowing an attacker to store malicious JavaScript code in WordPress content. When a user views the compromised page, the injected script runs in their browser, potentially stealing credentials, hijacking sessions, or defacing the site. This flaw permits arbitrary code execution in the context of the victim’s browser, jeopardizing confidentiality, integrity, and the user experience. The weakness is identified as CWE‑79, which reflects insufficient sanitization of user-supplied data.
Affected Systems
This flaw affects the bPlugins B Blocks plugin for WordPress, specifically all releases up to version 2.1.8 inclusive. The vulnerability is present from the earliest version (n/a) through 2.1.8, and users of any of these versions are at risk if the plugin is activated on a live site.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and currently the EPSS score is unavailable, so the exploitation probability cannot be quantified precisely. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed widespread exploitation at this time. However, stored XSS is a common attack vector and can be triggered by any user with permission to add or edit content that the plugin processes. An attacker controlling content input could embed malicious scripts that execute for all visitors who view the affected pages, making the risk contingent on the plugin’s use case and the site’s access controls.
OpenCVE Enrichment