Impact
The Menu Card plugin for WordPress contains a stored Cross‑Site Scripting vulnerability that is triggered by the category parameter in shortcodes. Attackers who possess Contributor or higher privileges can insert arbitrary JavaScript into the parameter value. When a page containing the malicious shortcode is viewed, the script runs in the browser context of any user who loads that page, allowing phishing, credential theft, or defacement of the site.
Affected Systems
The flaw affects the Menu Card plugin authored by furqan-khanzada, version 0.8.0 and any earlier releases. Users running any of these vulnerable versions on a WordPress installation are at risk. No other products or vendors are listed as impacted.
Risk and Exploitability
With a CVSS score of 6.4, the vulnerability is considered moderate severity. The EPSS score is below 1%, suggesting low current exploitation likelihood, and the issue is not present in the CISA KEV catalog. However, authenticated attackers with Contributor-level access, which many CMS administrators assign to trusted staff, can exploit the flaw by inserting a malicious shortcode. Successful exploitation results in script execution in the browser of any subsequent page visitor, compromising confidentiality and potentially allowing further attacks.
OpenCVE Enrichment