Impact
The ESV Bible Shortcode for WordPress plugin contains a stored XSS flaw (CWE‑79) that originates from the plugin’s 'esv' shortcode. Insufficient input sanitization and output escaping allow an attacker with contributor or higher privileges to inject arbitrary scripts via shortcode attributes. Once stored, these malicious scripts run whenever a user views the affected page, enabling defacement, session hijacking, or phishing attacks. The vulnerability does not grant remote code execution; it is limited to client‑side script execution within the context of the site’s users.
Affected Systems
This flaw affects any site using calebzahnd’s ESV Bible Shortcode for WordPress plugin up to and including version 1.0.2. The plugin is used in WordPress installations, and a contributor‑level account or higher can exploit the issue.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% implies a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated user exploiting the shortcode functionality, which requires no additional privilege escalations beyond existing contributor access.
OpenCVE Enrichment
EUVD