Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw that allows an attacker to embed malicious script code into pages served by the WordPress Brave Conversion Engine (PRO) plugin. When a user visits a page that includes the vulnerable plugin, the injected script can run in the victim’s browser. This enables an attacker to steal session cookies, deface content, or redirect users to malicious sites. The weakness is identified as CWE-79 and is caused by improper input sanitization in plugin code.
Affected Systems
The issue affects the Brave Conversion Engine (PRO) plugin distributed by AmpleByte Pvt Limited, versions 0.8.6 and earlier. WordPress sites that install or are running these plugin versions are at risk.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The attack likely requires the attacker to lure a user into visiting a page that processes untrusted input from the plugin, meaning the threat is real even without public exploit code. The potential for widespread exploitation exists as the plugin is widely used; however, mitigations are straightforward.
OpenCVE Enrichment