Impact
A flaw in the FluentCommunity plugin permits a subscriber to inject arbitrary scripts into the browsing context of other subscribers. The vulnerability is a classic Cross‑Site Scripting weakness (CWE‑79) that could allow an attacker to hijack sessions, deface content, or exfiltrate data while a user is logged into the site.
Affected Systems
The issue exists in WPManageNinja’s FluentCommunity plugin for WordPress up to version 2.7.5, inclusive. Versions 2.7.7 and later contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. No EPSS data is available, and the flaw is not listed in CISA KEV. The likely attack vector is a web‑based exploitation of the subscriber interface, where a malicious payload could be submitted and reflected or stored, enabling execution in the victim’s browser.
OpenCVE Enrichment