Impact
The Surbma | MiniCRM Shortcode plugin for WordPress is vulnerable to stored cross‑site scripting because the "id" attribute of the "minicrm" shortcode is not sanitized or escaped. An attacker who can add or modify content containing this shortcode can inject arbitrary JavaScript that will be executed in the browsers of any visitor who views the affected page. This is a classic client‑side injection flaw classified as CWE‑79.
Affected Systems
All WordPress sites running any version of the Surbma | MiniCRM Shortcode plugin up to and including 2.0 are affected. The flaw requires an authenticated user with Contributor permissions or higher to add or edit content that includes the vulnerable shortcode.
Risk and Exploitability
The CVSS score of 6.4 places the vulnerability in the medium‑to‑high range. The EPSS score is below 1% and the flaw is not listed in the CISA KEV catalog, indicating a relatively low current exploitation likelihood. However, because it allows authenticated contributors to embed malicious scripts that execute for every site visitor, the risk is significant in sites where contributor roles have broad content editing rights.
OpenCVE Enrichment