Impact
The vulnerability exists in the Bold Timeline Lite plugin for WordPress, allowing injected scripts to be stored in the "supertitle" and "subtitle" attributes of the bold_timeline_item shortcode. Contributors or higher‑privileged users can input arbitrary code through these fields, and the plugin fails to sanitize or escape the values before rendering them on the page. When a page containing the compromised shortcode is visited, the embedded JavaScript runs in the victim’s browser, enabling attackers to deface content, steal session cookies, or perform other client‑side attacks.
Affected Systems
WordPress sites using the Bold Timeline Lite plugin with versions 1.2.8 or earlier are affected. The issue arises when the plugin processes user‑supplied attributes for the bold_timeline_item shortcode through the WordPress content editing interface.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited widespread exploitation. The attack requires authenticated access with at least Contributor privileges, and the malicious script is stored and executed only when users view the affected page. The risk is primarily to site administrators and site visitors who trigger the injected code, and the impact is confined to client‑side execution rather than server‑side compromise.
OpenCVE Enrichment