Impact
The CMB2 WordPress plugin contains a stored XSS flaw in the 'file_list' field type due to inadequate sanitization and output escaping. An attacker can embed malicious scripts that will run in the browser of any visitor who loads a page containing the injected value. This can lead to session hijacking, data theft, or defacement of the site. The vulnerability is classified as CWE‑79 and results in a CVSS score of 7.2.
Affected Systems
Any WordPress site that uses CMB2 version 2.13.0 or older and that registers a public file_list field through an integrating plugin or theme. The issue does not exist in later CMB2 releases; thus sites running ≥2.13.1 are not affected. Vulnerability is limited to publicly exposed front‑end forms or user meta boxes that expose file_list fields.
Risk and Exploitability
The CVSS score of 7.2 indicates moderate to high severity, but the exploitability depends on whether a public file_list field is present. Because the EPSS score is not available and the vulnerability is not listed in CISA KEV, the overall risk is considered medium; however sites that expose the vulnerable field to unauthenticated users face a high likelihood of successful exploitation if an attacker obtains a payload. The attack vector is client‑side, making the discovery and exploitation straightforward for anyone who can influence the form content.
OpenCVE Enrichment