Impact
The Islamic Phrases plugin for WordPress is affected by a stored Cross‑Site Scripting flaw where the ‘phrases’ shortcode attribute is not properly sanitized or escaped. Because the vulnerability is accessible to authenticated users with contributor-level privileges or higher, an attacker can inject malicious scripts that will execute each time a page containing the injected shortcode is loaded by any site visitor. This flaw directly maps to CWE‑79 and jeopardizes the confidentiality and integrity of user sessions and site content.
Affected Systems
The flaw applies to all releases of the Islamic Phrases WordPress plugin up to and including version 2.12.2015. The plugin is distributed under the darto vendor identifier. Any WordPress installation that has this plugin version installed and is exposed to contributors or higher roles is vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate to high severity, while the EPSS score of less than 1 % shows that exploitation is unlikely at the time of this analysis. The vulnerability is not listed in CISA’s KEV catalog. Attackers must first authenticate to the WordPress site with at least contributor rights and then edit or create content that uses the dangerous ‘phrases’ shortcode. Once the malicious payload is stored, it runs automatically for every viewer of the affected page, making it a significant threat if compromised credentials or elevated roles are available.
OpenCVE Enrichment