Impact
The Social Media Shortcodes plugin for WordPress is vulnerable to stored cross‑site scripting via the 'twitter' shortcode. The flaw stems from insufficient input sanitization and output escaping of user‑supplied attributes, allowing contributors and higher‑level users to inject arbitrary JavaScript into the plugin’s output. When an attacker embeds a malicious payload in a shortcode attribute, the script executes automatically for any visitor who loads the affected post, enabling defacement, credential theft, or other client‑side attacks. This weakness is identified as CWE‑79.
Affected Systems
The vulnerability affects the Social Media Shortcodes plugin (tw2113) for WordPress. All releases up to and including version 1.3.1 are impacted, while newer releases may contain a fix.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity, but the EPSS score of less than 1% and the requirement for authenticated contributor‑level access reduce the likelihood of exploitation in the wild. The plugin does not appear in the CISA KEV catalog, suggesting no known active exploitation. Attackers must first have valid contributor credentials to inject malicious payloads via the shortcode, after which the injected script runs in the context of every visitor’s browser.
OpenCVE Enrichment
EUVD