Impact
The vulnerability is an unescaped cross‑site scripting flaw present in all releases of the WordPress Tabs plugin up to and including version 2.5. It allows an attacker to inject arbitrary JavaScript into content that is rendered to visitors of the site, potentially impacting data confidentiality and integrity of the website. No other consequences are specified in the official description.
Affected Systems
WordPress sites that have installed the Tabs plugin from wpshopmart (Tabs) with a version equal to or older than 2.5 are affected. The flaw applies to any installation where the plugin is active and renders user‑supplied content without sanitization.
Risk and Exploitability
The CVSS score of 5.9 classifies the flaw as moderate severity. The EPSS score is less than 1% indicating a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s user interface or configuration pages, where a malicious actor can input crafted content that will be displayed unescaped to site visitors, as inferred from the nature of a reflected XSS flaw.
OpenCVE Enrichment