Impact
The flaw allows an attacker to inject malicious scripts that run in a visitor’s browser when subscriber data rendered by the CMB2 plugin is displayed. The resulting client‑side XSS is capable of hijacking sessions or defacing the site.
Affected Systems
WordPress installations that include the CMB2 plugin by Justin Sternberg, version 2.13.0 or earlier, are affected.
Risk and Exploitability
This vulnerability is triggered when user‑supplied subscriber input is rendered by the plugin, so an attacker can create a payload that executes in the victim’s browser. The CVSS score of 6.5 indicates medium severity, the EPSS score is not available, and the issue is not listed in CISA KEV, implying no widespread exploitation yet. The likely attack vector is injection of malicious script into the subscriber interface that is subsequently displayed to site visitors.
OpenCVE Enrichment