Impact
The dbview WordPress plugin contains a stored cross‑site scripting flaw in its shortcode handling because user supplied attributes are not properly sanitized or escaped. This results in the ability to inject malicious scripts that will be stored in the database and served to any visitor who loads the affected page. The impact is the execution of attacker‑controlled JavaScript in the context of the site, which can lead to session hijacking, defacement or further compromise of site data.
Affected Systems
The vulnerability affects all releases of the dbview plugin from the John Ackers project up to and including version 0.5.5. WordPress sites that deploy these versions are susceptible when contributor‑level or higher users insert content that contains the vulnerable shortcode.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, but the EPSS score is below 1% suggesting a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Attack requires authentic access with contributor privileges or higher, so it is an insider or credential‑based attack vector. An attacker who satisfies this prerequisite can inject scripts that execute in any user's browser, leading to potential credential theft, redirect or defacement.
OpenCVE Enrichment
EUVD