Impact
The Arconix Shortcodes plugin for WordPress permits stored cross‑site scripting through improper input neutralization. Attackers can inject malicious scripts that execute in the victim’s browser when the stored content is displayed, potentially exfiltrating data or performing unauthorized actions on behalf of the user. This stored XSS flaw compromises confidentiality, integrity, and availability for any users interacting with the affected content. The weakness is classified as CWE‑79.
Affected Systems
The plugin is distributed by TycheSoftwares under the name Arconix Shortcodes. Versions up to and including 2.1.17 are affected. Users managing WordPress sites that have this plugin installed should check the current version at the time of evaluation.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate to high severity, but the EPSS score of less than 1 % suggests that exploitation of this vulnerability is currently unlikely. It is listed as not in the CISA KEV catalog, implying no widespread active exploitation is known. Attackers would need the ability to submit data that is stored by the plugin, then persuade or trick a victim into viewing that data; the vulnerability is a classic stored XSS scenario and typically requires no privileged access to the target system.
OpenCVE Enrichment
EUVD