Impact
The Pet‑Manager – Petfinder WordPress plugin is vulnerable to a stored cross‑site scripting flaw that is triggered through the kwm-petfinder shortcode. In all versions up to 3.6.1 the plugin does not properly sanitise or escape attributes supplied to the shortcode, allowing an attacker to persistently embed arbitrary JavaScript. When a user views the affected page, the injected script executes in the victim’s browser, enabling theft of session cookies, defacement, or other malicious client‑side actions. The primary weakness is reflected in CWE‑79, and the impact is limited to the web application’s front‑end but could lead to broader compromise if credentials are stolen.
Affected Systems
WordPress sites installing the Pet‑Manager – Petfinder plugin from the vendor kwmanagement. All releases through version 3.6.1 are affected; newer releases are not listed as vulnerable in the data provided.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the near term, and the vulnerability is not yet present in the CISA KEV catalog. Attackers require authenticated Contributor‑level (or higher) access to the WordPress site, which allows them to insert the malicious shortcode. Once injected, the payload continues to affect all users who view the page, making the risk aggregated across site visitors.
OpenCVE Enrichment