Impact
The GNA Search Shortcode plugin contains an Improper Neutralization of Input During Web Page Generation flaw that enables stored cross‑site scripting. Because the plugin does not sanitize input properly, a malicious user can insert code that will be executed whenever the stored content is rendered, potentially compromising users who view or interact with the affected pages.
Affected Systems
The vulnerability affects the WordPress GNA Search Shortcode plugin from its inception through version 0.9.5. The plugin is distributed by the developer Chris Mok.
Risk and Exploitability
The CVSS score of 6.5 classifies the issue as moderate severity. The EPSS score of <1% indicates a low probability of exploitation at this time and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to find or create a context in which the plugin accepts user‑supplied content that is then stored and rendered, but no special permissions or network access are required to carry out the exploit.
OpenCVE Enrichment
EUVD