Impact
The Subpage List plugin for WordPress contains a stored cross‑site scripting flaw in versions up to 1.3.3. The flaw resides in the handling of the 'subpages' shortcode, where user‑supplied attributes are not properly sanitized or escaped. As a result, an authenticated contributor or higher can inject arbitrary JavaScript into the page content that will execute for any visitor who views the affected page.
Affected Systems
WordPress sites that run Subpage List version 1.3.3 or earlier are affected. The vulnerability does not extend to other plugins or core WordPress components. Any installation that has not upgraded beyond 1.3.3 remains vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to first authenticate with contributor‑level credentials or higher. Once authenticated, the attacker can insert malicious attributes into the shortcode, causing a stored XSS that triggers when any user loads the offending page.
OpenCVE Enrichment
EUVD