Impact
The Boost plugin for WordPress contains an unauthenticated cross‑site scripting flaw that enables attackers to inject arbitrary JavaScript into the site. This flaw can result in defacement, phishing, or the theft of user session data if a user views a page affected by the injected code. The weakness is a classic injection vulnerability and is identified as CWE‑79.
Affected Systems
Affected products include the WordPress Boost plugin from PixelYourSite Professional. All releases up to and including version 2.0.4 are vulnerable, as the CVE indicates that Boost versions 2.0.4 or earlier contain the flaw.
Risk and Exploitability
The CVSS score of 7.1 reflects a high risk level, and the vulnerability is not listed in CISA’s KEV catalog. EPSS data is not available, but the unauthenticated nature of the flaw means that any external user can trigger the injection, making it likely to be exploited if the plugin remains in use. Because no official workaround exists, the only effective remediation is to update or remove the vulnerable plugin.
OpenCVE Enrichment