Impact
White Label CMS contains a stored cross‑site scripting flaw in its admin settings, allowing an authenticated user with administrator privileges to inject arbitrary JavaScript that will execute whenever a site visitor accesses a page containing the injected data. The vulnerability is rooted in insufficient input sanitisation and output escaping, which is classified as CWE‑79.
Affected Systems
All installations of White Label CMS produced by videousermanuals with a version of 2.7.12 or earlier are vulnerable. The flaw only presents itself unfiltered_html capability is disabled; single‑site installations or sites with unfiltered_html enabled do not experience this vulnerability.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate severity, while the EPSS score of less than 1% points to a low likelihood of real‑world exploitation at this time. The issue is not included in the CISA KEV catalog. Exploitation requires an attacker to possess administrative or higher privileges on the WordPress installation, which limits the risk compared to an unauthenticated flaw, yet the stored XSS still poses significant risk to all users who view pages containing the compromised settings.
OpenCVE Enrichment