Impact
The STM Gallery plugin is vulnerable to stored cross‑site scripting through the composicion parameter in all versions up to 0.9 due to insufficient input sanitization and output escaping. An authenticated attacker with Contributor or higher access can inject arbitrary JavaScript that executes whenever a user views an affected page.
Affected Systems
The vulnerability affects the STM Gallery plugin for WordPress, developed by sergiotoca, in all releases up to and including version 0.9. The issue resides in how the plugin processes the composicion shortcode attribute without proper sanitization.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score is less than 1%, suggesting a low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker has authenticated Contributor-level access or higher, after which they can inject malicious scripts into pages that will run for any user who loads the compromised content.
OpenCVE Enrichment