Impact
The Mindmeister Shortcode plugin does not properly neutralize user input during web page generation, allowing an attacker to inject malicious JavaScript that is executed in the context of the victim’s browser. This DOM‑based XSS enables execution of malicious scripts in the victim’s browser.
Affected Systems
WordPress sites that have installed the Mindmeister Shortcode plugin by thom4, including all releases up to and including 1.0. Any instance of this plugin running on a WordPress installation is vulnerable.
Risk and Exploitability
The vulnerability receives a CVSS score of 6.5, indicating moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation in the current environment. It is not listed in the CISA KEV catalog. The attack is client‑side and can be triggered by a visitor who loads content that incorporates the vulnerable shortcode, making it exploitable through normal website traffic.
OpenCVE Enrichment
EUVD