Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nitethemes Nite Shortcodes nite-shortcodes allows Stored XSS.This issue affects Nite Shortcodes: from n/a through <= 1.0.
Published: 2025-01-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Nite Shortcodes plugin for WordPress contains a flaw that allows malicious JavaScript to be stored and subsequently rendered within web pages. When an attacker is able to inject code that the plugin accepts and retains, that code appears on pages viewed by other users. Executed scripts can steal session cookies, modify page content, or redirect users to phishing sites, thereby compromising confidentiality, integrity, or availability of the web application from the client side.

Affected Systems

Any WordPress installation that has the nitethemes Nite Shortcodes plugin with a version from the earliest release through 1.0 is vulnerable. Sites that still run or have retained configuration information from those versions should be reviewed.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of early exploitation. The vulnerability is not listed in the CISA KEV catalog. To exploit this flaw an attacker would need to insert a malicious payload into a data field that the plugin accepts and stores – based on the description it is inferred that such a field likely exists for content or shortcode entry. Once stored, any visitor to the affected page will have the script executed, potentially enabling session hijacking or other client‑side attacks.

Generated by OpenCVE AI on May 2, 2026 at 06:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the nitethemes Nite Shortcodes plugin to a version newer than 1.0, ensuring the patch is applied.
  • If an upgrade cannot be performed, deactivate or uninstall the Nite Shortcodes plugin to eliminate the vulnerability.
  • Review existing posts, pages, or shortcodes for embedded JavaScript and remove or sanitize any suspicious code before re‑publishing.

Generated by OpenCVE AI on May 2, 2026 at 06:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3498 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nitethemes Nite Shortcodes allows Stored XSS.This issue affects Nite Shortcodes: from n/a through 1.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nitethemes Nite Shortcodes allows Stored XSS.This issue affects Nite Shortcodes: from n/a through 1.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nitethemes Nite Shortcodes nite-shortcodes allows Stored XSS.This issue affects Nite Shortcodes: from n/a through <= 1.0.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Fri, 17 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 16 Jan 2025 20:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nitethemes Nite Shortcodes allows Stored XSS.This issue affects Nite Shortcodes: from n/a through 1.0.
Title WordPress Nite Shortcodes plugin <= 1.0 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:23.325Z

Reserved: 2025-01-16T11:31:27.428Z

Link: CVE-2025-23877

cve-icon Vulnrichment

Updated: 2025-01-17T17:17:10.316Z

cve-icon NVD

Status : Deferred

Published: 2025-01-16T21:15:28.963

Modified: 2026-06-17T08:57:39.673

Link: CVE-2025-23877

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T06:15:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')