Impact
The vulnerability is a stored cross‑site scripting flaw that stems from the My Geo Posts Free plugin not escaping the default attribute of the 'mygeo_city' shortcode. An attacker with contributor‑level access can inject arbitrary JavaScript into the shortcode, which is persisted and executed whenever a user loads a page containing the shortcode.
Affected Systems
The affected product is the WordPress plugin "My Geo Posts Free" from vendor mindstien. All released versions up to and including 1.2 are vulnerable. No newer releases are listed in the provided data.
Risk and Exploitability
The CVSS score of 6.4 places the vulnerability in the medium severity range. The EPSS score of less than 1% indicates the probability of exploitation is very low, and the vulnerability is not currently listed in the CISA KEV catalog. Attack requires an authenticated user with at least contributor privileges; the attacker then exploits the stored XSS to affect all site visitors who view the impacted page.
OpenCVE Enrichment