Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1.
Published: 2025-10-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation that allows an attacker to store malicious JavaScript code through the Memberlite Shortcodes plugin. When the content is later rendered, the script executes in the browser of any visitor, giving the attacker a range of possibilities including theft of credentials, session hijacking, defacement of page content, or distribution of malware. The weakness is identified as CWE‑79 and results in a loss of confidentiality, integrity and, in some cases, availability of the affected web application.

Affected Systems

This flaw affects the WordPress plugin "Memberlite Shortcodes" developed by Jason C. The vulnerability is present in all releases up to and including version 1.4.1. Any WordPress site that has installed or upgraded to a version of the plugin no later than 1.4.1 is potentially impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of less than 1% shows that current exploitation activity is very low; however, the flaw is not listed in CISA’s KEV catalog, meaning no widespread known exploits have been reported yet. Attackers can exploit the defect by submitting a malicious payload through the plugin’s input fields, which is stored and later returned to unsuspecting visitors. As the attack does not require special network privileges, any compromised site that has the plugin installed can be used as a vector to deliver the script to its users.

Generated by OpenCVE AI on April 30, 2026 at 05:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Memberlite Shortcodes plugin to the latest version that addresses the stored XSS flaw; the patch is available through the plugin’s official update channel.
  • If an immediate update is not possible, disable the plugin’s shortcode functionality or remove the plugin entirely from the WordPress installation to eliminate the vulnerability.
  • Perform a content audit to locate and delete any scripts or suspicious markup that may have been injected into posts or pages, and restart the WordPress cache so that any cached malicious content is purged.

Generated by OpenCVE AI on April 30, 2026 at 05:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 19:45:00 +0000


Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through <= 1.4.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1.
References

Thu, 23 Apr 2026 15:45:00 +0000


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through <= 1.4.1.
References

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 20 Oct 2025 13:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 17 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Oct 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jason C. Memberlite Shortcodes memberlite-shortcodes allows Stored XSS.This issue affects Memberlite Shortcodes: from n/a through 1.4.1.
Title WordPress Memberlite Shortcodes plugin <= 1.4.1 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:50.384Z

Reserved: 2025-05-15T17:54:23.204Z

Link: CVE-2025-48087

cve-icon Vulnrichment

Updated: 2025-10-17T14:37:12.995Z

cve-icon NVD

Status : Deferred

Published: 2025-10-17T15:15:38.730

Modified: 2026-04-28T19:32:34.427

Link: CVE-2025-48087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T06:00:12Z

Weaknesses