Impact
The vulnerability is an Improper Neutralization of Input During Web Page Generation flaw that allows attackers to inject malicious scripts into webpages through the Fusion Builder plugin. This stored XSS flaw can be used to alter the content seen by users. The weakness corresponds to CWE‑79: Improper Neutralization of Input during Web Page Generation.
Affected Systems
The issue affects the ThemeFusion Fusion Builder plugin from its earliest releases up through version 3.14.1. Any WordPress installation using Fusion Builder prior to version 3.14.1 is vulnerable. Specific vendor the plugin is from ThemeFusion under the Fusion Builder name.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1 % suggests a low probability of exploitation at any given time, and the vulnerability is not listed in CISA’s KEV catalog. Attackers could exploit the flaw via any interface that accepts content for the plugin, such as page or post editors, by supplying malicious JavaScript that will later be rendered for other site visitors. No special privileges are required beyond the ability to submit content to the affected plugin.
OpenCVE Enrichment