Impact
The Survey Anyplace plugin for WordPress contains a Stored Cross‑Site Scripting flaw in its surveyanyplace_embed shortcode. Because the plugin fails to sanitize and escape user‑supplied attributes, an authenticated attacker with contributor‑level access or higher can inject arbitrary JavaScript into the page. When a visitor loads any page that contains the malicious shortcode, the injected script runs in the visitor’s browser, enabling actions such as cookie theft, session hijacking, defacement, or execution of other malicious payloads.
Affected Systems
WordPress installations that use the Survey Anyplace plugin version 1.0.0 or earlier are affected. The vulnerability is present in all releases up to, and including, 1.0.0.
Risk and Exploitability
The CVSS score of 6.4 reflects moderate impact, while the EPSS score of less than 1 % indicates a low exploitation probability in the wild. The flaw is not publicly exploitable; it requires the attacker to be authenticated with at least contributor privileges. Once the attacker injects payloads through the shortcode, any user who visits the page executes the malicious script. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD