Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hkharpreetkumar1 AIO Shortcodes aio-shortcodes allows Stored XSS.This issue affects AIO Shortcodes: from n/a through <= 1.3.
Published: 2025-02-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The AIO Shortcodes plugin versions up to 1.3 contain a flaw where user‑provided content is stored without adequate escaping. When that content is later rendered, an attacker’s JavaScript can execute in the victim’s browser. This allows unauthorized code execution in the context of any user who views the affected page. The weakness corresponds to CWE‑79 and does not require elevated privileges beyond normal content‑editing rights.

Affected Systems

WordPress sites that have installed the hkharpreetkumar1 AIO Shortcodes plugin version 1.3 or earlier are vulnerable, regardless of the WordPress core version. The issue manifests in both the administrative interface, where users can submit or edit content, and the public‑facing pages where that content is displayed.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate‑to‑high severity, while the EPSS score below 1% suggests that current exploitation attempts are unlikely; the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the potential impact is substantial because arbitrary JavaScript can run in any visitor’s browser. The likely attack vector is the submission of malicious content through the plugin’s shortcode feature, which an attacker can do if they have a role that permits content creation or editing. No special authentication is required beyond typical author or administrator privileges.

Generated by OpenCVE AI on May 2, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest AIO Shortcodes plugin version (1.4 or later) to remove the vulnerable implementation.
  • If the plugin is unnecessary, uninstall or deactivate it to eliminate the attack surface.
  • If a timely update is not possible, limit the ability to add or edit content that uses the shortcode, and ensure any stored text is properly sanitized or escaped before rendering.

Generated by OpenCVE AI on May 2, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-3823 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AIO Shortcodes allows Stored XSS. This issue affects AIO Shortcodes: from n/a through 1.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AIO Shortcodes allows Stored XSS. This issue affects AIO Shortcodes: from n/a through 1.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hkharpreetkumar1 AIO Shortcodes aio-shortcodes allows Stored XSS.This issue affects AIO Shortcodes: from n/a through <= 1.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00035}

epss

{'score': 0.00045}


Mon, 03 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound AIO Shortcodes allows Stored XSS. This issue affects AIO Shortcodes: from n/a through 1.3.
Title WordPress AIO Shortcodes plugin <= 1.3 - Stored Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-11T23:26:54.991Z

Reserved: 2025-01-23T14:51:18.436Z

Link: CVE-2025-24620

cve-icon Vulnrichment

Updated: 2025-02-03T16:55:14.086Z

cve-icon NVD

Status : Deferred

Published: 2025-02-03T15:15:26.697

Modified: 2026-06-17T08:59:19.847

Link: CVE-2025-24620

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T09:30:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')