Impact
The vulnerability allows an attacker to inject arbitrary JavaScript into the web pages served by WordPress sites that use the Team Section Block plugin version 2.0.4 or earlier. Because authentication is not required to deliver the malicious code, a person who can access the site can cause the site to execute script in the browsers of any visitor, potentially leading to defacement, cookie theft, or other client‑side attacks.
Affected Systems
The affected software is the bPlugins Team Section Block plugin. All WordPress installations using this plugin version 2.0.4 or earlier are vulnerable. No additional version details are supplied, but the issue applies to every release up to and including 2.0.4.
Risk and Exploitability
The CVSS score of 7.1 classifies the flaw as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits as of the current data. Because the flaw can be triggered without authentication, an attacker who can construct web requests to the site can deliver the malicious payload, making exploitation likely where the plugin is enabled.
OpenCVE Enrichment