Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw caused by improper neutralization of input during web page generation. User‑controlled data that passes through the Hello Bar Popup Builder plugin can be reflected into the browser context, allowing an attacker to inject and execute arbitrary JavaScript when the page is viewed.
Affected Systems
WordPress sites that have installed the Hello Bar Popup Builder plugin version 1.5.1 or earlier. The plugin is developed by telepathy under the name Hello Bar Popup Builder.
Risk and Exploitability
The CVSS score of 6.5 places the flaw in the medium severity range. The EPSS score is below 1 percent, suggesting that exploitation is uncommon at present, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need to get the affected page to load the plugin and supply malicious data that is reflected into the DOM; if successful, the compromised user’s browser would run the injected script. Overall, the risk is moderate, and repeated exploitation would only affect client‑side contexts rather than the server directly.
OpenCVE Enrichment