Impact
A stored cross‑site scripting flaw exists in the Spectra Gutenberg Blocks plugin’s uagb/image block, allowing authenticated users with Contributor or higher privileges to insert arbitrary JavaScript that is saved in the database and executed whenever any visitor loads a page containing the injected image block. The weakness is a classic input validation and output escaping failure, identified as CWE‑79. As a result, scripts run with the context of the page, potentially enabling the attacker to read or modify page content, capture user data, or insert further malicious payloads.
Affected Systems
The vulnerability affects the Brainstormforce Spectra Legacy – Gutenberg Blocks WordPress plugin in all released versions up to and including 2.19.28. Earlier releases are not impacted by this flaw.
Risk and Exploitability
The flaw carries a CVSS score of 6.4 and an EPSS score of less than 1 %, indicating a low probability of widespread exploitation, and it is not listed in the CISA KEV catalog. However, the attack vector is authenticated; any site user with Contributor-level access or higher can exploit the issue. Once an attacker succeeds, the injected scripts will run for all users who view the affected page, potentially leading to data theft or further propagation of malware.
OpenCVE Enrichment