Impact
Unauthenticated Cross Site Scripting is present in the Knowledge Base for Documentation, FAQs with AI Assistance plugin for WordPress. An attacker can inject malicious scripts that execute in the browsers of users who view affected pages, potentially enabling session hijacking, defacement, or the execution of arbitrary client‑side code. The weakness maps to CWE‑79, a classic input validation flaw.
Affected Systems
The vulnerability affects the echoplugins WordPress Knowledge Base for Documentation, FAQs with AI Assistance plugin in any release up to and including 17.211.0. All sites running those versions are exposed; newer releases are not impacted.
Risk and Exploitability
With a CVSS score of 7.1, the issue is considered medium severity. No exploit probability score is reported, and the vulnerability is not listed in the CISA KEV catalog. Because authentication is not required and the flaw can be triggered via any user visiting a rendered FAQ or documentation page, the risk of exploitation is realistic, especially on sites with high traffic or publicly exposed content. Adopting a defensive web‑application firewall or content‑security‑policy headers can mitigate the impact until a patch is applied. The most common attack path involves crafting malicious URLs or content that the plugin renders, which an attacker can disseminate through social engineering or brute‑force catalog exploration.
OpenCVE Enrichment