Impact
The Posts Slider Shortcode plugin contains a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject malicious script into a page rendered by the plugin. An attacker could embed attacker‑controlled data into a shortcode or comment that is not properly encoded before being displayed in the browser. Successful exploitation could lead to theft of a user’s session cookies, defacement of content, or the execution of arbitrary JavaScript in the context of the victim’s browser.
Affected Systems
The vulnerability exists in the Posts Slider Shortcode plugin by Aakif Kadiwala for WordPress, affecting all versions up to and including 1.0. WordPress sites that have installed this plugin are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog and the likely attack vector is a client‑side injection where a malicious payload is embedded in a request that triggers the plugin’s output. If an attacker can influence the content seen by other users, they may be able to compromise their sessions or inject malicious content.
OpenCVE Enrichment
EUVD