Impact
The Builderall for WordPress plugin contains a data‑validation flaw in the Photo Module ’attributes’ setting that allows a contributor or higher privileged user to store malicious JavaScript. When a user views the affected photo page, the injected script runs in that visitor’s browser. This can lead to session hijacking, credential theft, defacement or spreading of malware to other users of the site.
Affected Systems
All installations of Builderall for WordPress version 3.0.2 or older are vulnerable, regardless of the WordPress core version. The flaw exists in the Photo Module files and the associated AJAX handlers that persist the user input.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, giving it a moderate severity. No EPSS score is publicly available, and the weakness is not listed in CISA's KEV catalog, so there is no evidence of widespread exploitation yet. The flaw requires authenticated access, so only sites with contributor‑level users exposed to the Photo Module are at risk, but once accessed the injected code runs for all visitors who load the page.
OpenCVE Enrichment