Impact
The vulnerability is a stored cross‑site scripting flaw that arises when the Rescue Shortcodes plugin fails to neutralize input before rendering it in web pages. Because the plugin accepts arbitrary shortcode content, an attacker who can influence that content can embed malicious JavaScript that will run in the browsers of anyone who views the affected page. Such scripts could hijack user sessions, steal cookies, or redirect visitors, compromising confidentiality and integrity of site users.
Affected Systems
All releases of the Rescue Shortcodes plugin for WordPress up to and including version 3.1 are affected, as the flaw is present from the earliest available revision through 3.1. Any site that remains on these versions, regardless of how old, is exposed.
Risk and Exploitability
The CVSS score of 6.5 places the flaw in the medium impact range, and the EPSS value of less than 1% indicates that exploitation is unlikely at the time of assessment. The vulnerability is not listed in the CISA KEV catalog. The likely attack surface arises through the plugin’s admin interface, where an authenticated user can create or edit shortcodes that store data permanently. By inserting malicious code into these shortcodes, an attacker can execute payloads on any page that renders the content, giving them the ability to target both authenticated and unauthenticated site visitors.
OpenCVE Enrichment
EUVD