Impact
The Shortcode for Google Street View plugin for WordPress is vulnerable to stored cross‑site scripting because the 'id' attribute of the 'streetview' shortcode is not properly sanitized or escaped. An authenticated user with contributor or higher permissions can inject arbitrary JavaScript into the shortcode, which is stored in the page content and executed whenever any user views the affected page, potentially leading to defacement, cookie theft, or further malicious activity.
Affected Systems
The vulnerable plugin is “Shortcode for Google Street View” by Antioch Interactive, affecting all releases up to version 0.5.7; no patched versions are listed in the supplied data.
Risk and Exploitability
The CVSS score of 6.4 denotes medium severity, but an EPSS score of less than 1 % indicates a low probability of exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires an authenticated contributor or higher account to inject malicious content; once embedded, the stored script will be executed for all visitors to pages containing the shortcode, offering a widespread XSS attack surface.
OpenCVE Enrichment