Impact
The Snow Monkey Blocks plugin for WordPress contains a stored cross‑site scripting flaw resulting from insufficient sanitization of the 'data-slick' attribute in all releases up to 24.1.11. An attacker with authenticated Contributor‑level access can inject arbitrary JavaScript that will execute in the context of any visitor who views an affected page. The CVE description does not specify particular downstream effects; however, because the script runs client‑side, it could potentially be used for hostile actions typical of stored XSS, such as defacement or credential theft, which are inferred and not explicitly documented in the official description.
Affected Systems
The vulnerability applies to the WordPress plugin Snow Monkey Blocks produced by inc2734. All plugin releases with a version number of 24.1.11 or lower are affected. The issue is confined to sites running any WordPress installation that has the vulnerable plugin active.
Risk and Exploitability
The calculated CVSS score of 6.4 points to moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The attack vector is authenticated; an attacker must log in to the WordPress site with at least Contributor privileges to inject the malicious script. Once injected, the script runs in the context of any visitor who views the affected page.
OpenCVE Enrichment