Impact
The RPB Chessboard plugin in WordPress suffers from a stored Cross‑Site Scripting vulnerability in comment content. Unsanitized user input is accepted and later rendered with a comment_text filter that appends dangerous attributes, allowing an attacker to inject executable scripts. Those scripts run in the context of any user who accesses the affected page, enabling session hijacking, defacement, or other client‑side compromises.
Affected Systems
WordPress sites that deploy the RPB Chessboard plugin version 8.1.2 or earlier from vendor yo35 are affected. Any installation that has not upgraded beyond this version is vulnerable.
Risk and Exploitability
This flaw has a CVSS score of 7.2, indicating high severity; the EPSS score is less than 1%, implying that exploitation is relatively uncommon. The vulnerability requires no authentication – an unauthenticated attacker can submit malicious comment payloads that will be rendered when other users view the page – and it is not listed in CISA’s KEV catalog.
OpenCVE Enrichment