Impact
Improper neutralization of input during web page generation in the NerdPress Hubbub Lite plugin allows stored XSS, meaning malicious JavaScript can be persisted and served to visitors when they view the affected.
Affected Systems
The vulnerability affects the NerdPress Hubbub Lite WordPress plugin from all released versions up through 1.36.3. Any installation of these versions that relies on the plugin’s user‑input handling is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of current exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, an attacker would most likely exploit the vulnerability by submitting malicious input through the plugin’s front‑end form or administration interface, which is then stored and later rendered to visitors.
OpenCVE Enrichment