Impact
The Rise Blocks – A Complete Gutenberg Page Builder plugin for WordPress is vulnerable because the ‘logoTag’ Site Identity block attribute does not sanitize input or escape output, allowing an authenticated user with Contributor level access or higher to store arbitrary JavaScript. Once the script is stored, it executes in the browsers of any visitor who loads the affected page, enabling theft of session cookies, phishing, or loading of malicious resources.
Affected Systems
All installations of Rise Blocks – A Complete Gutenberg Page Builder through version 3.7 are affected. Any WordPress site that has deployed the plugin in these versions is at risk, regardless of the source of installation.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1 % suggests a low but non‑zero likelihood of exploitation. Because an attacker needs authenticated Contributor access, the vulnerability is not remote, but the stored script poses an ongoing risk to all page viewers once injected. The vulnerability is not listed in CISA's KEV catalog, reinforcing the low exploitation probability at present.
OpenCVE Enrichment