Impact
Unauthenticated Cross‑Site Scripting (XSS) exists in the HollerBox plugin for WordPress versions 2.3.10.1 and earlier. The flaw allows an attacker to inject arbitrary JavaScript into the output rendered by the plugin. This could lead to session hijacking, defacement of the site, or delivery of malicious content to visitors, all without any authentication.
Affected Systems
WordPress installations running the Groundhogg HollerBox plugin at version 2.3.10.1 or any earlier release are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.1, indicating a high severity impact. The EPSS score is less than 1 %, suggesting a very low current exploitation probability. The flaw is not listed in the CISA KEV catalog, and there is no known public exploit. Based on the description, it is inferred that the attack vector is the web front‑end, allowing any site visitor to trigger the flaw without authentication, which can impact a wide range of users until the plugin is patched or disabled.
OpenCVE Enrichment