Impact
The Live Photos on WordPress plugin stores user‑supplied values for the 'video_src', 'img_src', and 'class' attributes of the livephotos_photo shortcode without proper sanitization or escaping. This flaw allows a contributor‑level attacker to inject arbitrary JavaScript that will run when a page containing the stored data is loaded by a user. The injected script executes within the context of the site, giving the attacker the ability to perform client‑side attacks such as defacing content, redirecting users, or collecting information from the victim’s browser.
Affected Systems
The affected product is the Live Photos on WordPress plugin developed by eggemplo. All released versions up to and including 0.1 are vulnerable. Users who have deployed any of those versions are at risk until they upgrade or remove the plugin.
Risk and Exploitability
The CVSS score for this vulnerability is 6.4, indicating a moderate level of severity. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is low, and it is not listed in the CISA KEV catalog. The attack requires authenticated access with at least contributor privileges and the ability to edit content that contains the shortcode. An attacker who succeeds can inject malicious scripts that will execute for any user who views the affected page, potentially leading to a range of client‑side attacks.
OpenCVE Enrichment