Impact
The LiveJournal Shortcode WordPress plugin, up to version 1.1.1, fails to properly validate and escape certain shortcode attributes before they are rendered in posts and pages. This oversight allows users with at least contributor permissions to embed arbitrary code that will be executed in the browsers of any visitor reading the affected content. The flaw represents a classic client‑side injection vulnerability (CWE‑79).
Affected Systems
WordPress environments running the LiveJournal Shortcode plugin up to and including version 1.1.1 are affected. The plugin vendor is not formally listed; the product should be identified as the 'LiveJournal Shortcode' WordPress plugin in versions 1.1.1 and below.
Risk and Exploitability
The overall CVSS score of 5.9 classifies this vulnerability as moderate. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting that mass exploitation is not ongoing. The likely attack vector involves a malicious contributor injecting crafted shortcode attributes that contain harmful JavaScript, which then get stored in the post database and later rendered to all site visitors. The impact is limited to the roles that can add or edit content (contributors and higher).
OpenCVE Enrichment