Impact
The vulnerability is a stored Cross‑Site Scripting flaw that allows an attacker to inject arbitrary HTML and JavaScript into web pages rendered by the Meks Flexible Shortcodes plugin. If executed, the injected code can run in the context of logged‑in users, potentially exfiltrating sensitive data, hijacking sessions or defacing the site.
Affected Systems
All installations of the Meks Flexible Shortcodes WordPress plugin with a version of 1.3.6 or earlier are impacted. This includes every site running any pre‑1.3.6 release of the plugin.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of <1% shows a low but non‑zero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation. Based on the description, it is inferred that the likely attack vector is the creation of a malicious shortcode containing script payloads that is stored via the plugin’s interface or data import mechanisms; the stored data would then be rendered on any page that processes the affected shortcode, leading to widespread exposure across the site.
OpenCVE Enrichment
EUVD