Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw that allows an attacker to inject arbitrary JavaScript into pages served by the WP w3all phpBB plugin. This can lead to session hijacking, defacement, or drive‑by downloads for users who visit vulnerable pages. The weakness is a classic reflected or stored XSS, classified as CWE‑79.
Affected Systems
The plugin through version 3.0.6 is impacted. WordPress sites that include the WP w3all phpBB plugin installed on any theme or custom setup are vulnerable. No specific WordPress core version is referenced, so all installations that have not upgraded beyond 3.0.6 are at risk.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high‑severity risk. Because the flaw is unauthenticated and does not require any credentials, an attacker can exploit it directly by crafting a malicious URL or link to a user who accesses the compromised site. The EPSS score is not available, but the lack of a KEV listing does not reduce the likelihood that it could be used in the wild. Sites are advised to assume active exploitation until a patch is applied.
OpenCVE Enrichment