Impact
The Stock Tools plugin for WordPress contains a stored cross‑site scripting flaw in the 'image_height' and 'image_width' shortcode attributes. Because user input is not sanitized or escaped, authenticated users with contributor role or higher can inject malicious JavaScript. When an attacker embeds crafted attribute values in a page, every visitor—including administrators—will have the script executed in their browser. The vulnerability allows arbitrary JavaScript execution in the context of any user who views the affected page.
Affected Systems
All versions of the developdaly Stock Tools WordPress plugin up to and including 1.1 are affected. The flaw exists in the PHP code that processes the shortcode attributes 'image_height' and 'image_width' in those releases. Users running those versions on any WordPress site are at risk as soon as a contributor or higher role exists.
Risk and Exploitability
The weakness is rated CVSS 6.4, indicating a moderate severity. The EPSS score is less than 1 %, suggesting that exploitation is low probability at present, and the flaw is not listed in CISA’s KEV catalog. Nonetheless, because the attack requires only contributor‑level access—a fairly common role on many WordPress sites—an authenticated attacker can reliably insert arbitrary JavaScript. The vulnerability can be triggered via normal usage of the plugin’s shortcode functionality and requires no special network access, implying a web application based attack vector.
OpenCVE Enrichment