Impact
The Wish To Go plugin for WordPress contains a stored cross‑site scripting vulnerability in its shortcode attributes. Unsanitized user input is stored in the database and rendered directly when a page containing the shortcode is loaded, allowing a logged‑in attacker with Contributor or higher privileges to inject arbitrary JavaScript that will execute in the browsers of anyone who views the affected page.
Affected Systems
All releases of jseto's Travel Bucket List – Wish To Go plugin up to and including version 0.5.2 are affected. The flaw can be exploited only on sites that use this plugin and have users with Contributor or higher roles who can create or edit content containing shortcodes.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication with at least Contributor privileges to add or edit a shortcode, after which the malicious script is stored and will run for any visitor who opens the associated page.
OpenCVE Enrichment