Impact
An improper neutralization of input during web page generation allows a stored cross‑site scripting flaw in the mcjh button shortcode WordPress plugin. This weakness, classified as CWE‑79, permits attackers who can inject arbitrary script into stored content to execute malicious JavaScript in the browsers of users who view that content. The consequences include session hijacking, defacement, data theft, and the ability to spread malware to site visitors.
Affected Systems
The vulnerability affects the mcjh button shortcode plugin developed by Marcus C. J. Hartmann for WordPress, in all releases up to and including version 1.6.4. Any WordPress site that has installed this plugin within that version range is potentially exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to be able to input malicious content into the plugin’s shortcode interface or have administrative rights to add content that contains the exploit. Once the stored script is rendered, all site visitors are affected.
OpenCVE Enrichment
EUVD