Impact
The CVE‑2025‑13448 vulnerability exists in the CSSIgniter Shortcodes plugin for WordPress up to version 2.4.1. It is caused by insufficient input sanitization and output escaping for the 'element' shortcode attribute, allowing an attacker who can create or edit posts to inject arbitrary JavaScript that will execute whenever any user views the affected page. This stored cross‑site scripting can lead to session hijacking, data theft, or site defacement.
Affected Systems
Affected vendors: Anastis, product: CSSIgniter Shortcodes for WordPress. All releases up to and including 2.4.1 are vulnerable. The plugin is commonly installed on WordPress sites that use this shortcode. Sites running a newer release such as 2.4.2 or later have the fix. No other vendors or products are known to be affected by this issue.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of <1% suggests a very low current exploitation probability. The vulnerability is not currently listed in CISA’s KEV catalog, but any authenticated user with Contributor role or higher can create a post containing a malicious 'element' attribute, which will then execute as XSS in the browsers of all visitors to that page. Attackers need only legitimate editing privileges; no additional system or network access is required.
OpenCVE Enrichment