Impact
The Reviews Sorted plugin for WordPress suffers from stored cross‑site scripting in all releases up to 2.4.2. An authenticated user with Contributor level or higher can embed malicious script code through the 'space' attribute of the [reviews-slider] shortcode, which is then rendered and executed in the browsers of visitors who view the affected page. The flaw is caused by insufficient input sanitization and a lack of output escaping, enabling attackers to steal session cookies, deface content, or launch further attacks.
Affected Systems
WordPress sites running Reviews Sorted version 2.4.2 or earlier, produced by eurisko:Reviews Sorted.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating medium severity, and an EPSS score of less than 1%, suggesting a low current exploitation probability. It is not listed in the CISA KEV catalog, so no public exploits are known. However, the requirement for authenticated Contributor+ access means any site granting such roles is at risk, and exploitation could affect all users who view injected content.
OpenCVE Enrichment