Impact
The vulnerability is a classic Cross Site Scripting flaw in the WordPress Landing Page Builder plugin through version 1.5.3.5. An attacker can inject malicious script code that is rendered and executed by browsers of any visitor who loads the affected page. The flaw does not require authentication and therefore is exploitable by anyone with access to the website, enabling the execution of arbitrary client‑side code within the site’s domain scope.
Affected Systems
Any WordPress site that has the PluginOps Landing Page Builder plugin installed in a version older than 1.5.3.6 is affected. The issue spans all releases up to and including 1.5.3.5 of the plugin, regardless of installation method.
Risk and Exploitability
The CVSS score of 7.1 classifies the vulnerability as high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, indicating it is potentially exploitable but has no known widespread operational exploitation. Attackers can exploit the flaw simply by delivering a crafted webpage that includes the malicious script, which the browser will execute without any user‑authentication requirement.
OpenCVE Enrichment