Impact
The DobsonDev Shortcodes plugin has a stored cross‑site scripting flaw where input to generated pages is not properly neutralized. When content that includes malicious script tags is saved by the plugin, those scripts are rendered in subsequent views of the page, allowing code to execute in the browsers of visitors. This can occur whenever page content managed by the plugin is accessed.
Affected Systems
WordPress installations that include DobsonDev Shortcodes plugin version 2.1.12 or earlier are vulnerable. The flaw exists from the earliest release up through 2.1.12.
Risk and Exploitability
The base CVSS score of 6.5 categorizes the issue as medium severity, while the EPSS score under 1% points to a low likelihood of exploitation at present. The vulnerability is not included in CISA’s KEV collection. Because the flaw arises from data entered into the plugin’s content fields, the likely attack vector is remote, enabled by an attacker who can submit such content and then have it displayed to web users.
OpenCVE Enrichment
EUVD