CPE
The CMB2 plugin for WordPress (<= 2.13.0) is vulnerable to Stored XSS via the file_list field type, allowing unauthenticated attackers to inject malicious scripts into public-facing forms or user meta boxes.