Impact
The Smart App Banners WordPress plugin allows stored cross‑site scripting through the 'size' and 'verticalalign' parameters of its 'app‑store‑download' shortcode. Because input is not sufficiently sanitized or properly escaped, an authenticated user with Contributor access or higher can inject JavaScript that will run whenever any visitor loads a page containing the malicious shortcode, giving the attacker the ability to deface content, steal data, or perform further attacks.
Affected Systems
WordPress sites that have installed the Smart App Banners plugin, version 1.2 or any earlier release. The vulnerability exists in all releases up to and including 1.2, so any site using the plugin in those versions is impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need authenticated Contributor‑level or higher access to inject the malicious shortcode; once the shortcode is stored, all visitors to the relevant page will have the injected script executed, providing a direct path for exploitation without additional prerequisites.
OpenCVE Enrichment