Impact
The vulnerability is an unauthenticated XSS in BBQ Pro plugin up to version 3.9. It permits an attacker to inject malicious scripts that run in the browser of any user who views the affected page. Because authentication is not required, any internet user could trigger the injection, potentially hijacking sessions, defacing content, or delivering malware. The weakness maps to CWE‑79, indicating improper handling of user input before output.
Affected Systems
WordPress sites running Jeff Starr’s BBQ Pro plugin at version 3.9 or earlier are affected. The flaw is present in all releases from the first version up to and including 3.9; users should verify the installed version from the Plugins page.
Risk and Exploitability
The CVSS score of 7.1 indicates a high impact. The EPSS score of 0.00146 suggests a very low probability of exploitation, but the combination with a high vulnerability severity remains a concern. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploits yet; however, the lack of authentication checks means any attacker could potentially exploit it if the plugin’s vulnerable fields are reachable. Immediate patching is advised.
OpenCVE Enrichment