Impact
The PullQuote plugin for WordPress allows authenticated users with contributor-level access to store arbitrary JavaScript in shortcode attributes, resulting in stored cross‑site scripting attacks whenever the affected page is viewed. Because the plugin does not sanitize or escape these attributes, an attacker can inject malicious scripts that execute in the browsers of all site visitors, potentially compromising credentials, defacing content, or exfiltrating data.
Affected Systems
WordPress sites running the PullQuote plugin version 1.0 or earlier are affected. Administrators should verify the installed version; any instance that has not been updated beyond 1.0 is at risk.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating a moderate severity, and an EPSS score of less than 1 %, suggesting a very low current exploitation probability. It is not listed in CISA’s KEV catalog. The attack requires an authenticated contributor or higher role, meaning the threat is most relevant to sites that permit many content editors or where attacker credentials are obtained.
OpenCVE Enrichment