Impact
The Hello Bar Popup Builder plugin contains a flaw that improperly neutralizes user input during page rendering, producing a DOM‑based cross‑site scripting vulnerability. An attacker can inject malicious JavaScript into a page that contains the plugin, which executes automatically in the victim’s browser when the page is viewed. The injected code can steal session cookies, deface the page, or perform other client‑side attacks on the user.
Affected Systems
All installations of the telepathy Hello Bar Popup Builder plugin with versions from the earliest available release through 1.5.1 are impacted. WordPress sites that have not upgraded beyond version 1.5.1 are vulnerable, regardless of other security controls in place.
Risk and Exploitability
The vulnerability operates entirely on the client side; no authentication or privileged access is required, which is inferred from the lack of any mention of a privilege prerequisite. The absence of EPSS and KEV entries suggests the exploit is not currently known, yet the ease of crafting a malicious URL or social‑engineering a victim gives the flaw a moderate to high risk rating. Prompt remediation is recommended.
OpenCVE Enrichment