Impact
The vulnerability in the HootBoard WordPress plugin allows an attacker to submit data through unsecured REST endpoints that are not protected by an authorization check. The data stored by these endpoints is subsequently rendered on a public page without any escaping, enabling arbitrary JavaScript to be injected. Because the script runs in the context of any visitor, an attacker could hijack sessions, steal credentials, deface pages, or perform further malicious actions as the site administrator.
Affected Systems
All WordPress sites that have the HootBoard plugin installed with a version through 3.1.4 are affected. The issue is present in the plugin’s configuration REST endpoint, and no vendor version beyond 3.1.4 has been specified as vulnerable in the current disclosure.
Risk and Exploitability
The vulnerability is a significant risk due to its lack of authentication and its potential to compromise any user who views the affected page, including administrators. No EPSS score is available and the flaw is not listed in CISA’s KEV catalog, but the description indicates that the flaw can be exploited by unauthenticated users. The absence of an EPSS value means that built‑in exploitation probability estimates are not currently available, yet the documented flaw suggests a high likelihood of exploitation if the plugin is not patched. The CVSS score is not provided in the disclosure, so a formal severity assessment is unavailable; however, the nature of the flaw warrants a high‑severity response.
OpenCVE Enrichment