Impact
The WP Js List Pages Shortcodes plugin contains a stored Cross‑Site Scripting flaw in the "class" shortcode attribute in all releases up to and including 1.21. Because the plugin does not sanitize or escape that attribute, a malicious contributor or higher can inject arbitrary JavaScript that will run in the browser of any visitor to a page containing the injected shortcode. This can lead to credential theft, defacement or other malicious actions performed in the victim’s context.
Affected Systems
WordPress sites that have the WP Js List Pages Shortcodes plugin installed with a version 1.21 or earlier. The vulnerability is limited to installations that use the "class" attribute in the plugin’s shortcode but any user with access to a page containing such a shortcode is at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS value of < 1% shows that the overall probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local: an attacker must first gain authenticated Contributor-level access, after which they can inject the payload via the shortcode and cause exploitation when any site visitor views the affected page.
OpenCVE Enrichment