Impact
The CVE describes a contributor‑side Cross Site Scripting flaw in the BSK PDF Manager plugin for WordPress, affecting all releases up to and including version 3.8. An attacker is able to provide input that the plugin subsequently renders without proper sanitisation, allowing execution of arbitrary JavaScript in the context of the site.
Affected Systems
The BSK PDF Manager plugin from bannersky, versions 3.8 and older, is vulnerable. Any WordPress site with this plugin installed exposes a risk of XSS if a contributor role is available to submit content. Site administrators should verify the installed plugin version and take corrective action.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score being below 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA's KEV catalogue. Based on the description the attack vector requires a contributor role to submit input, making it an authenticated threat likely limited to users with such permissions.
OpenCVE Enrichment