Impact
The Recras WordPress plugin contains a stored cross‑site scripting flaw that occurs when the "recrasname" shortcode attribute is not properly sanitized or escaped for output. An attacker who has Contributor or higher privileges can inject malicious JavaScript into that attribute. When any user views a page containing the shortcode, the injected code runs in the victim’s browser, allowing the attacker to steal session cookies, deface the site, or load additional payloads.
Affected Systems
The vulnerability affects the Recras WordPress plugin developed by zanderz, specifically all releases up to and including 6.4.1. Site administrators using any of those versions are at risk if WordPress users with Contributor or higher roles can edit content that includes the affected shortcode.
Risk and Exploitability
With a CVSS score of 6.4, the flaw is considered moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely at the moment, and the vulnerability is not listed in the CISA KEV catalog. However, because only Contributor‑level access is required—which is common on many WordPress installations—an attacker who compromises such credentials can quickly embed scripts that affect all visitors to the compromised page.
OpenCVE Enrichment