Impact
The Shabat Keeper plugin for WordPress contains an input handling flaw that allows malicious script payloads to be reflected into page output when the value of $_SERVER['PHP_SELF'] is used without proper sanitization or escaping. This vulnerability is classified as CWE‑79 and can enable arbitrary JavaScript to run in the context of a victim’s browser when a user follows a specially crafted link. The resulting impact can include cookie theft, session hijacking, or the execution of further malicious actions through the browser.
Affected Systems
All installations of the Shabat Keeper plugin version 0.4.4 and earlier are affected. The plugin is developed by beshkin and is available within the WordPress plugin repository. No other vendor or product variants are listed in the CNA data.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, while the EPSS score of less than 1% suggests a currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can introduce the script by creating a link containing the malicious payload, relying on a victim’s willingness to click it. No authentication or privileged access is required, making this issue widely exploitable in public or untrusted user contexts.
OpenCVE Enrichment