Impact
The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to reflected cross‑site scripting due to inadequate sanitization and escaping of the page parameter. The flaw allows an unauthenticated attacker to embed arbitrary JavaScript that executes when an administrator follows a crafted link. This creates the risk of session hijacking, cookie theft, or other malicious actions performed under the administrator’s authority.
Affected Systems
Plugins affected are the CBX 5 Star Rating & Review WordPress plugin versions up to and including 1.0.7, developed by Manchumahara. No other vendor or product is listed.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV catalog. Exploitation requires no privileged user context; an attacker only needs to lure an administrator to click a link bearing malicious script in the page query string, making it a low‑barrier XSS attack that could compromise an admin’s session.
OpenCVE Enrichment