Impact
The Everviz plugin for WordPress contains a stored cross‑site scripting flaw that occurs when the plugin fails to properly sanitize the type and hash attributes of the everviz shortcode. In versions through 1.1 this can allow an authenticated user with contributor-level privileges or higher to inject arbitrary JavaScript that will be executed whenever any user views an affected page. The injected script can steal credentials, hijack sessions, deface content, or deliver malware, compromising the confidentiality, integrity, or availability of the site for all viewers of the compromised content.
Affected Systems
WordPress sites using the everviz plugin content delivery system. The vulnerability applies to all releases through 1.1 of the Everviz plugin.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of malicious exploitation at this time. The flaw is not listed in the CISA KEV catalog. Exploitation requires an authenticated user with contributor or greater privileges and the ability to create or edit content that includes the vulnerable shortcode. No current public exploit code is known, so the risk primarily lies in internal users with sufficient role permissions.
OpenCVE Enrichment