Impact
The vulnerably described is a Contributor Cross Site Scripting flaw in the WordPress BetterDocs plugin versions up to 4.6.2. This weakness allows an attacker who can create or edit content as a contributor to inject arbitrary HTML or JavaScript that will be rendered in the browsers of visitors to the site. The impact is the execution of malicious scripts in the context of the site, potentially leading to theft of session cookies, defacement, or further lateral movement. The weakness is identified as CWE‑79, a classic XSS vulnerability.
Affected Systems
WordPress sites that have installed the WPDeveloper BetterDocs plugin with a version 4.6.2 or earlier are affected. Users of this plugin, whether administrators, editors or contributors, may be exposed if the plugin is present and not updated.
Risk and Exploitability
The CVSS score of 6.5 places this flaw in the medium severity category. The EPSS score is below 1% (approximately 0.0013), indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not on an active exploit list. The most likely attack vector requires an attacker to either become a contributor on the site or exploit existing contributor privileges. Once that condition is met, a malicious payload can be injected via the plugin’s content editing interface and will be executed in the browsers of any user that views the affected content.
OpenCVE Enrichment