Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Reflected XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.15.
Published: 2025-04-17
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper neutralization of input during web page generation in tychesoftwares Arconix Shortcodes plugin versions up to 2.1.15 allows attackers to inject malicious scripts into reflected responses. The flaw is a classic reflected cross‑site scripting vulnerability (CWE‑79). An attacker can craft a URL that includes script payloads; when a victim clicks the link or is tricked into visiting it, the embedded script runs inside the victim’s browser, enabling cookie theft, session hijacking, and potential transmission of further malicious content.

Affected Systems

The affected product is the Tychesoftwares Arconix Shortcodes WordPress plugin. All versions from the initial release through version 2.1.15 are vulnerable. Update references list the plugin as impacting all releases up to the listed minor version; because no starting version is specified, it is inferred that all earlier releases may also be affected.

Risk and Exploitability

The CVSS score is 7.1, indicating high severity for a client‑side attack. The EPSS score is below 1 %, suggesting a low exploitation likelihood at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based and does not require authentication; based on the description it is inferred that attackers can construct the exploit from any public endpoint that accepts user‑supplied parameters. Because the flaw is reflected, a single malicious URL can affect any user who visits it, while the lack of a user‑input state or additional privileges keeps the context limited to the victim’s browser.

Generated by OpenCVE AI on May 2, 2026 at 01:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Arconix Shortcodes to the latest available version (at least 2.1.16)
  • If an upgrade is not immediately possible, disable the plugin or remove any shortcodes that echo untrusted data
  • Sanitize or escape all user‑supplied data when using the plugin’s shortcodes, ensuring that no raw input is reflected in the HTML output
  • As a temporary measure, consider implementing a web‑application firewall rule or “x-web-compat” header to mitigate reflected XSS attacks

Generated by OpenCVE AI on May 2, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-11605 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.15.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.15. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes arconix-shortcodes allows Reflected XSS.This issue affects Arconix Shortcodes: from n/a through <= 2.1.15.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Thu, 17 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arconix Shortcodes allows Reflected XSS. This issue affects Arconix Shortcodes: from n/a through 2.1.15.
Title WordPress Arconix Shortcodes plugin <= 2.1.15 - Reflected Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Tychesoftwares Arconix Shortcodes
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T23:57:54.345Z

Reserved: 2025-01-23T14:51:18.436Z

Link: CVE-2025-24621

cve-icon Vulnrichment

Updated: 2025-04-17T17:43:20.687Z

cve-icon NVD

Status : Deferred

Published: 2025-04-17T16:15:32.947

Modified: 2026-04-23T15:25:09.077

Link: CVE-2025-24621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T02:00:15Z

Weaknesses