Impact
The vulnerability allows an authenticated contributor or higher to inject arbitrary JavaScript that is stored in the database and executed whenever the affected page is viewed. This stored Cross‑Site Scripting can be used for defacement, cookie theft, session hijacking, or injection of malicious payloads into other users’ browsers.
Affected Systems
The flaw is present only in the AH Shortcodes WordPress plugin released by ahecht, for all versions up to and including 1.0.2. The affected component is the column shortcode attribute, which is part of the plugin’s shortcodes system on WordPress sites that have the plugin installed.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% signals a low probability of active exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user with Contributor‑level access to create or edit content containing a column shortcode with malicious script, and the script will then execute for all visitors to the edited page. The impact is confined to the user’s session when the page is loaded, but an attacker can hijack sessions or spread malware across the site.
OpenCVE Enrichment