Impact
The weDocs plugin for WordPress is vulnerable to stored cross‑site scripting (CWE‑79) through the 'connectorWidth' block attribute because input is not sanitized and output is not escaped. Authenticated users with contributor‑level privileges and above can embed arbitrary JavaScript into visitor views that page, the injected script executes in the visitor’s browser, but whether it allows remote code execution on the server is not explicitly described; based on the information provided, it appears that the plugin does not permit RCE on the server.
Affected Systems
The vulnerability exists in all versions of the weDocs plugin up to and including version 2.3.0. Any WordPress installation that has this plugin at one of those versions is affected. the product is the AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin.
Risk and Exploitability
The CVSS score of 6.4 classifies the flaw as moderate. The EPSS score is less than 1%, indicating a. The vulnerability is not listed in KEV., compromised accounts; once access is achieved, exploitation is straightforward and impacts all users who view the compromised page.
OpenCVE Enrichment