Impact
The Ibtana – WordPress Website Builder plugin contains a stored cross‑site scripting flaw. In every release up to and including 1.2.5.7 the 'ive' shortcode processes user‑supplied attributes without proper sanitization or escaping. An attacker who can authenticate as a contributor or higher role can inject arbitrary JavaScript into a page. When another visitor opens that page the injected script runs in the visitor’s browser, potentially stealing credentials, redirecting to malicious sites or displaying unwanted content.
Affected Systems
The vulnerability affects the Ibtana – WordPress Website Builder plugin for WordPress, supplied by vowelweb. All versions from the initial release through 1.2.5.7 are impacted. Any WordPress site that has this plugin enabled, with users that have contributor or higher privileges, is at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. With no publicly reported exploit data or EPSS score, the exploitation probability is unclear, but the vulnerability requires an authenticated user with contributor access or higher, which many site administrators grant. Because the attack injects code that executes for all users who view the page, untrusted content can be shown to visitors, leading to data theft or fraud. Site owners should treat this as a medium‑to‑high risk until a patch is applied.
OpenCVE Enrichment