Impact
The Responsive and Swipe Slider plugin for WordPress contains a stored cross‑site scripting flaw (CWE‑79) in the rsSlider shortcode. Unsanitized and unescaped user‑supplied attributes permit an attacker with contributor‑level access to embed malicious JavaScript that will run whenever any user visits the page containing the shortcode.
Affected Systems
The vulnerability exists in all releases of the Responsive and Swipe Slider plugin, up to and including version 1.0.2, supplied by the vendor mansoormunib.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity. EPSS is less than 1 %, implying a low likelihood of exploitation in the wild, and the flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated with at least contributor privileges; once they can edit a page, the injected code will persist and execute for every visitor to that page.
OpenCVE Enrichment