Impact
The vulnerability is a DOM‑based Cross‑Site Scripting flaw caused by improper neutralization of user‑supplied input during page generation. An attacker can embed arbitrary client‑side script that executes in the browser of any user who views a compromised page. The injected script runs with the privileges of the victim’s browser.
Affected Systems
WordPress sites that use the Envision Page Builder plugin, version 0.22 or earlier, including any earlier releases whose version details are not specified.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to insert malicious input into the builder’s data fields, which is then rendered in the victim’s browser. Because the flaw manifests only when the crafted content is viewed, the risk is primarily to users who interact with pages built with the affected plugin.
OpenCVE Enrichment