Impact
The vulnerability lies in the 'spacing' attribute of the nh_row shortcode in the Niche Hero WordPress plugin. Insufficient input sanitization and lack of output escaping allow an authenticated user with Contributor level access or higher to store malicious JavaScript in a page. When the victim visits the modified page, the injected script runs in the victim’s browser, enabling theft of session data, defacement, or redirection.
Affected Systems
This issue affects the Niche Hero plugin for WordPress versions up to and including 1.0.5. Any WordPress installation that has this plugin installed and allows Contributor‑level or higher users to edit content is in scope.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% implies low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires valid authentication; an attacker must first gain or already have Contributor access and then inject the payload via the spacing attribute, which is stored and later rendered on page load.
OpenCVE Enrichment