Impact
The WP Company Info plugin contains a stored cross‑site scripting flaw in the ‘class’ attribute of the ‘social‑networks’ shortcode. When an attacker with Contributor or higher permissions injects malicious JavaScript, the payload is saved in the database and runs each time a page containing the shortcode is viewed. This client‑side code execution can lead to session hijacking, defacement or data exfiltration within the victim’s browser environment.
Affected Systems
All WordPress sites using the WP Company Info plugin by bdeleasa in any release up to and including version 1.9.0 are potentially vulnerable. The issue is independent of the underlying operating system or host environment beyond WordPress.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. An attacker must first authenticate as a Contributor or higher, then insert a malicious ‘class’ value via the WordPress editor or another shortcode‑handling interface. Because the injected code is stored, any subsequent visitor to the affected page will execute the script, potentially expanding the impact to all site users.
OpenCVE Enrichment