Impact
An unauthenticated Cross Site Scripting flaw is present in the Soflyy Breakdance WordPress plugin version 2.7.1 and earlier, allowing an attacker to inject arbitrary client‑side code into pages generated by the plugin. The weakness, classified as CWE‑79, results from insufficient escaping or filtering of user‑supplied input, and an attacker can execute code in the browsers of visitors who load the affected pages. Such code execution can lead to cookie theft, session hijacking, defacement, or other malicious actions performed in the victim’s context.
Affected Systems
WordPress installations that have the Soflyy Breakdance plugin at version 2.7.1 or earlier are vulnerable; any site that has not upgraded to at least 2.7.2 is exposed to exploitation.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact, while the EPSS score of less than 1 % suggests exploitation is currently unlikely but still possible. The vulnerability is not listed in the CISA KEV catalog, yet it can be triggered by any attacker who can access the site’s public interface, as authentication is not required. The likely attack path involves the attacker delivering malicious input that the plugin accepts, which is then rendered unfiltered in the page output, causing script execution in the context of visiting users.
OpenCVE Enrichment