Impact
The Shortcode Button plugin for WordPress allows stored cross‑site scripting when a contributor or higher authenticates and inserts a malicious button shortcode. The plugin fails to sanitize and escape user supplied attributes, enabling arbitrary web scripts to be stored in a page and executed whenever any visitor loads that page. This flaw corresponds to CWE‑79.
Affected Systems
The vulnerability affects the eflyjason Shortcode Button plugin for WordPress, specifically all releases up to and including version 1.1.9. No other versions or products are mentioned as impacted.
Risk and Exploitability
The CVSS score of 6.4 places the vulnerability in a moderate severity category, while the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers must be authenticated with contributor or higher access, and the likely attack vector is an attacker editing a page to include a malicious button shortcode that injects JavaScript.
OpenCVE Enrichment