Impact
The vulnerability is a Cross Site Scripting flaw that allows malicious code to be injected via the contributor interface of the LIQUID SPEECH BALLOON WordPress plugin. The flaw is classified as CWE‑79 and can lead to the execution of arbitrary scripts in the context of the site owner’s browser, potentially enabling cookie theft, session hijacking, defacement or phishing attacks.
Affected Systems
This flaw affects the WordPress LIQUID SPEECH BALLOON plugin up to and including version 1.2.5. Sites running any of these versions are impacted. The vendor for the affected plugin is lqd.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score under 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require an authenticated contributor or content author with access to the plugin’s interface, delivering a malicious payload that is not properly escaped. The most probable attack vector is a user‑initiated action within the WordPress admin area that triggers the vulnerable code.
OpenCVE Enrichment