Impact
The plugin contains an unauthenticated XSS flaw that allows attackers to inject malicious scripts into web pages viewed by users. Based on the nature of the Cross Site Scripting weakness, it is inferred that exploitation could potentially enable session hijacking, defacement, or theft of user data.
Affected Systems
Kingtech LLC’s B2BKing Premium plugin for WordPress, specifically all releases up to and including 5.6.07. Any site running these versions is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, and the lack of an EPSS rating leaves the exact exploitation probability unclear. The attack requires no authentication and can be performed by sending crafted URLs to users; those users’ browsers will execute the injected script. Because the flaw is not listed in the CISA KEV catalog, no known active exploits are reported, but the potential impact remains significant for exposed WordPress installations.
OpenCVE Enrichment