Impact
Improper neutralization of input during web page generation allows a DOM‑based cross‑site scripting vulnerability in the pflonk Sidebar‑Content from Shortcode plugin. The flaw, classified as CWE‑79, enables an attacker to inject malicious JavaScript into a page that is rendered by the plugin, potentially compromising user data or manipulating site content when the victim interacts with the affected page.
Affected Systems
The vulnerability is present in all releases of the pflonk Sidebar‑Content from Shortcode plugin up to and including version 2.0, regardless of the installation context. WordPress sites that have this plugin installed with a version 2.0 or earlier are affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, and the EPSS score of less than 1% suggests that the likelihood of exploitation is currently low; the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a user‑containing shortcode or content that the plugin processes; an attacker would need to supply or modify content that is rendered by the plugin to inject script payloads. Once executed, the malicious code runs in the victim’s browser, potentially leading to data theft or session hijacking.
OpenCVE Enrichment
EUVD