Impact
The Vulnerable Sidebar Manager Light plugin accepts user input for the sbm_description field without adequate sanitization or escaping, allowing the injection of arbitrary JavaScript that will run in a victim’s browser when the affected page is loaded. An attacker can therefore execute client‑side code, steal session cookies, deface the site, or perform other malicious actions side‑effectively. No authentication is required to trigger the flaw, so any visitor can be affected by the injected payloads. The weakness is characterized as a classic Stored XSS issue drawn from CWE‑79.
Affected Systems
WordPress installations using Sidebar Manager Light version 1.18 or earlier are affected. The plugin is distributed by otwthemes and is included as the Sidebar Manager Light addon. Users running older or default WordPress setups with this plugin must verify their installed version.
Risk and Exploitability
The CVSS base score of 7.2 reflects the severity of the impact and the lack of authentication required for exploitation. The EPSS score is currently unavailable, but the flaw’s potential for widespread web‑based impact suggests it could be frequently sought after. The vulnerability is not yet listed in the CISA KEV catalog, indicating it may be newly discovered or not yet assessed for widespread exploitation. The attack vector is inferred from the description as unauthenticated web‑based input that persists in stored form, meaning that any user who views a page containing the injected sbm_description will have the script executed.
OpenCVE Enrichment