Impact
The Meks Flexible Shortcodes plugin contains a DOM‑based Cross‑Site Scripting flaw that allows an attacker to inject malicious scripts into a web page. This flaw involves improper input sanitization during page rendering and can lead to execution of arbitrary JavaScript in the context of the affected site, potentially enabling credential theft, defacement, or distribution of malware. The weakness is classified under CWE‑79 and carries a medium severity score.
Affected Systems
Meks Flexible Shortcodes plugins through version 1.3.7 are vulnerable. The issue is present in all builds prior to that release, regardless of the WordPress site version. Systems running any of these plugin versions are exposed to the XSS risk if they accept user‑generated shortcode content or other plugin inputs.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact, while the EPSS score of less than 1% suggests a low likelihood that current automated exploits are available. This vulnerability is not listed in the CISA KEV catalog. Attackers would need to deliver crafted content to a site using the affecting plugin, which can be achieved through admin or user posting interfaces. Once executed, the injected script runs with page privileges, allowing data exfiltration or further exploitation.
OpenCVE Enrichment
EUVD