Impact
The vulnerability is an instance of improper neutralization of input during web page generation, classified as a stored cross‑site scripting flaw. An attacker who can inject malicious input into the Easy Shortcode Buttons plugin may have that input saved in the database and then served to other users when the content is rendered, potentially enabling cookie theft, session hijacking, or defacement. The weakness is identified as CWE‑79, reflecting a failure to sanitize user input before output.
Affected Systems
The flaw affects the osuthorpe Easy Shortcode Buttons WordPress plugin, specifically all releases from the earliest version through version 1.2 inclusive. Any installation of this plugin below 1.2 is susceptible to exploitation.
Risk and Exploitability
With a CVSS base score of 6.5, the flaw is considered moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation in the near term. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to submit malicious input through editable fields provided by the plugin and then wait for the data to be rendered to victims, suggesting the attack vector is through the plugin’s input mechanisms or administrative interfaces.
OpenCVE Enrichment
EUVD