Impact
The CM Business Directory plugin for WordPress is vulnerable to stored cross‑site scripting through the 'cmbd_featured_image' shortcode. All releases up to and including 1.5.2 use insufficient input sanitization and output escaping when handling user‑supplied shortcode attributes, allowing an authenticated contributor or higher to inject arbitrary JavaScript that will execute for any visitor who loads an affected page. This flaw can lead to session hijacking, credential theft, defacement or the delivery of malware, compromising the confidentiality, integrity and availability of the site to users who view the injected page.
Affected Systems
The affected product is the CM Business Directory – Optimise and showcase local business from Creative Minds Solutions. All plugin versions up to and including 1.5.2 are vulnerable. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a low overall exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with at least contributor privileges. If successful, injected scripts run automatically for any anonymous or logged‑in user who visits the manipulated page, providing a broad attack surface for credential theft or defacement.
OpenCVE Enrichment
EUVD