Impact
The BrightTALK WordPress Shortcode plugin allows a contributor‑level user to add a brighttalk-time shortcode with a 'format' attribute that is not properly sanitized. This stored cross‑site scripting flaw permits injection of arbitrary JavaScript that will run whenever any visitor views the page containing the shortcode. The payload could steal session cookies, deface the site, or redirect users to malicious sites, thereby compromising confidentiality, integrity, and availability of the website content.
Affected Systems
WordPress sites that have the BrightTALK WordPress Shortcode plugin installed, version 2.4.0 or earlier, regardless of site configuration. An attacker must have contributor or higher privileges on the site. The affected product is the plugin by billybigpotatoes.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of <1% suggests very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires authenticated access with at least contributor role; once the attacker injects a malicious script, it executes in the browsers of any visitor to the affected page, exposing the site to client‑side attacks.
OpenCVE Enrichment