Impact
The FX Currency Converter plugin for WordPress contains a Stored Cross‑Site Scripting flaw caused by insufficient sanitization of the 'fxcc_convert' shortcode attributes. An authenticated attacker with contributor or higher privileges can inject arbitrary JavaScript that will run when a user views a page containing the shortcode. This vulnerability is categorized as CWE‑79 and enables malicious JavaScript to be executed in the browsers of users who view the infected content.
Affected Systems
The vulnerability affects the falselight FX Currency Converter WordPress plugin, version 0.2.0 and all earlier releases. The plugin is distributed through the WordPress.org repository and may be installed on any WordPress site that has the plugin enabled.
Risk and Exploitability
The CVSS base score is 6.4, indicating a moderate severity. An EPSS score of less than 1% suggests low but non‑zero risk of public exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog. Attackers must first authenticate with contributor-level access or higher; once authenticated, they can create or modify content that includes the malicious shortcode. Because the payload is stored and executed in the browser, any user who views the rendered page is exposed.
OpenCVE Enrichment