Impact
The vulnerability is a DOM‑based Cross‑site Scripting flaw caused by improper neutralization of input during web page generation in the Ultimate Addons for WPBakery Page Builder plugin. It allows an attacker to inject malicious scripts that are executed in a victim’s browser when the affected content is viewed.
Affected Systems
WordPress sites that run the Brainstorm Force Ultimate Addons for WPBakery Page Builder plugin in any version prior to 3.21.4 are affected.
Risk and Exploitability
The CVSS base score is 6.5, which is considered medium severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the exploit is likely feasible through the plugin’s input handling on the front‑end; authentication requirements are not specified, so the vulnerability could potentially be triggered by any user that can submit content to the plugin.
OpenCVE Enrichment