Impact
This vulnerability is an improper neutralization of user‑supplied input before rendering web pages, allowing attackers to persist malicious scripts in the database. An attacker could inject JavaScript that runs in the browsers of anyone viewing the affected page, leading to session hijacking, defacement, or delivery of malware. The weakness is identified as CWE‑79, a classic XSS flaw.
Affected Systems
The flaw affects the Shortcodes Ultimate plugin distributed by Vova, with all versions through 7.3.5. Users running any of those releases on WordPress sites are susceptible until a patched version is installed.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploit at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, and although it is a stored XSS, it would require an attacker to supply the malicious input via the plugin’s interface or a content‑creation process. The lack of widespread exploitation but the potential for serious impact make prompt attention advisable.
OpenCVE Enrichment
EUVD