Impact
The MediaPress WordPress plugin is vulnerable to a stored cross‑site scripting flaw caused by insufficient sanitization and output escaping of user‑supplied parameters in the mpp‑uploader shortcode. This weakness falls under CWE‑79 and allows a logged‑in user with contributor or higher privileges to inject arbitrary JavaScript that becomes part of the gallery content and is later rendered in the browser when other visitors view the page.
Affected Systems
The vulnerability affects any WordPress site running MediaPress plugin version 1.6.1 or earlier. Users with contributor‑level access or higher can edit gallery pages and exploit the flaw. It is limited to installations that have the plugin active and have not applied the vendor’s latest patch.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity for authenticated users. The EPSS score of less than 1% reflects a very low probability of real‑world exploitation, and the issue is not listed in the CISA KEV catalog. Nevertheless, because contributor roles are common on many sites, the potential for accidental or intentional compromise remains. An attacker would need to login, edit a gallery page, insert malicious shortcode, and then any visitor browsing that page would be subject to the injected script, enabling session hijacking, defacement, or phishing.
OpenCVE Enrichment