Impact
Improper neutralization of input during web page generation in the UIUX Lab Uix Shortcodes plugin allows attackers to store malicious scripts that will be executed when visitors load the affected page. This stored XSS flaw can be leveraged to steal session cookies, deface content, inject phishing payloads, or execute arbitrary client‑side commands. The vulnerability originates from unescaped data entered via the plugin’s input fields before being rendered in page output.
Affected Systems
All installations of the Uix Shortcodes plugin for WordPress with a version of 2.0.4 or earlier are affected. The vulnerability has no known version restrictions beyond the stated upper bound and applies broadly to all affected releases of the plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact on confidentiality, integrity, and availability, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog, implying no confirmed public exploits. The likely attack vector involves submitting malicious input through the plugin’s interface, which is then stored and later rendered as part of a page accessible to all users. Without mitigation, any user who views the affected page is at risk.
OpenCVE Enrichment
EUVD