Impact
The DesignThemes Core Features WordPress plugin up to version 4.8 contains a stored client‑side code‑injection flaw. Authenticated users with Contributor or higher roles can embed specially crafted shortcodes that include malicious attributes. When a user visits the affected page, the browser executes the injected script, potentially compromising user sessions or defacing content. The vulnerability stems from insufficient input sanitization and output escaping on user‑supplied attributes.
Affected Systems
The vulnerability affects the DesignThemes Core Features plugin for WordPress, specifically all released versions up to and including 4.8. Users who run these versions without applying a newer update are at risk.
Risk and Exploitability
The CVSS score is 6.4, indicating a moderate severity. The EPSS score is less than 1%, suggesting a very low probability of exploitation at present, and the issue is not listed in the CISA KEV catalog. Attackers must first obtain Contributor or higher access to the WordPress site and then supply a malicious shortcode; no unauthenticated or remote exploitation path is described.
OpenCVE Enrichment
EUVD