Impact
The vulnerability is a stored Cross‑Site Scripting flaw in the Bit Assist WordPress plugin. An attacker who is logged in with the privileged admin role can inject malicious JavaScript into the Call‑To‑Action feature. When other users view the content, the script is executed in their browsers, enabling the attacker to redirect them to a malicious site or potentially control their account through client‑side code.
Affected Systems
WordPress sites using the Bit Assist plugin with a version earlier than 1.7.2 are affected. Versions 1.7.2 and later contain the fix.
Risk and Exploitability
The CVSS score is not disclosed, but the flaw requires an authenticated admin credential and access to the plugin’s backend. The attack path is straightforward: login as admin, edit a call‑to‑action entry, and insert arbitrary script. Because the effect is executed in the visitor’s browser, it can lead to phishing, session hijack or cookie theft. The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, indicating that exploitation is not yet widely documented, yet the potential impact warrants moderate to high risk for sites that grant unrestricted admin rights to Bit Assist.
OpenCVE Enrichment