Impact
Cross‑Site Request Forgery enables an attacker to submit malicious data that the ShowTime Slideshow plugin stores verbatim and later presents without sanitization. When a user loads the affected slideshow the stored data is rendered inside the page and can execute scripts in the user’s browser, causing persistent Cross‑Site Scripting.
Affected Systems
WordPress sites that use the ShowTime Slideshow plugin from any unreleased version up through 1.6 are vulnerable. The product is provided by the vendor youtag under the ShowTime Slideshow name, with no additional version constraints beyond the 1.6 ceiling.
Risk and Exploitability
The CVSS score of 7.1 tags the flaw as high severity, but the EPSS score of less than 1 % indicates that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is CSRF, requiring the attacker to forge a request to the plugin endpoints. If such a request passes, the stored XSS can persist until the offending data is removed or the plugin is upgraded.
OpenCVE Enrichment
EUVD