Impact
The Sprout Clients plugin for WordPress contains an unauthenticated cross‑site scripting flaw, CWE‑79, that allows an attacker to inject malicious script into the plugin’s output. Because the input is not properly sanitized, any visitor to a page using the plugin can have arbitrary JavaScript executed in their browser session, which can be used to steal session cookies, deface content, or trick users into performing covert actions.
Affected Systems
All WordPress sites that have installed the BoldGrid Sprout Clients plugin version 3.2.3 or earlier are vulnerable; the issue resides in the Sprout Clients component of the plugin.
Risk and Exploitability
The CVSS score of 7.1 marks the flaw as high severity, while the EPSS score of less than 1% indicates that exploitation is considered unlikely and the vulnerability does not appear in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is a remote unauthenticated web request to the plugin, which allows arbitrary JavaScript execution in the victim’s browser. Although exploitation probability is low, the high potential impact warrants prompt remediation.
OpenCVE Enrichment