Impact
The BuddyHolis TableSearch WordPress plugin contains a stored cross‑site scripting flaw that allows authenticated users with Contributor level or higher to inject arbitrary JavaScript into the placeholder field. Because the plugin fails to properly sanitize and escape that input, the malicious code is persisted and rendered when the affected page is loaded. Any visitor to that page will execute the injected script in the context of the site’s domain, enabling credential theft, session hijacking, defacement, or other client‑side attacks. This weakness is a classic example of CWE‑79.
Affected Systems
The vulnerability applies to the BuddyHolis TableSearch plugin supplied by digiblogger for WordPress. All releases up to and including version 1.1.0 are affected. Site administrators should confirm whether the plugin is installed at a vulnerable version and plan to upgrade or remove it accordingly.
Risk and Exploitability
The CVSS score of 6.4 places the issue in the moderate‑severity range, while the EPSS score of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated Contributor‑level account; it does not provide server‑side code execution. The principal risk is that the client‑side script runs in every visitor’s browser when they load the stored entry.
OpenCVE Enrichment