Impact
The vulnerability is an unauthenticated Cross‑Site Scripting flaw that appears in versions of the WordPress Recipe Card Blocks for Gutenberg & Elementor plugin up to 3.4.18. An attacker can supply malicious script payloads, which the plugin passes directly to the browser without sanitisation, enabling the execution of arbitrary code within the context of a user’s session. This can lead to defacement, credential theft, and the delivery of further malware. The weakness corresponds to CWE‑79.
Affected Systems
This issue affects the WPZOOM "Recipe Card Blocks for Gutenberg & Elementor" plugin, specifically all releases version 3.4.18 and earlier.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. Although no EPSS value is currently available, the lack of an authentication requirement and the client‑side nature of the flaw signify a low barrier to exploitation. The vulnerability is not listed in the CISA KEV catalog, but because it can be triggered by unauthenticated users, it carries a significant risk profile. The likely attack vector is a crafted request or a user embedding malicious content into the plugin’s fields, which is then rendered in the browser without filtering.
OpenCVE Enrichment