Impact
The WP BBCode plugin is vulnerable to stored cross‑site scripting through its ‘url’ shortcode. Insufficient input sanitization and output escaping allow an authenticated user with contributor or higher privileges to embed arbitrary JavaScript that will run whenever an affected page is viewed, potentially exposing cookies, defacing content, or executing other malicious actions in the victim’s browser.
Affected Systems
The vulnerability affects the WordPress plugin WP BBCode by eflyjason. All releases up to and including version 1.8.1 are impacted. No other versions or products are mentioned.
Risk and Exploitability
The CVSS score of 6.4 classifies the issue as moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated contributor or higher user, meaning an attacker must first compromise or social‑engineer a user account with sufficient privileges to create or edit content that includes the vulnerable shortcode.
OpenCVE Enrichment