Description
The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Published: 2025-06-26
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting that can be triggered by authenticated users with contributor-level or higher access, leading to arbitrary script execution on visitor pages
Action: Patch
AI Analysis

Impact

The e.nigma Buttons plugin allows users with contributor-level or higher to embed a button shortcode. Because the plugin fails to validate or escape user supplied attributes, an attacker can store malicious JavaScript in the shortcode. When any visitor loads a page containing the contaminated button, the embedded script executes in the visitor’s browser.

Affected Systems

All WordPress installations running chemiker e.nigma Buttons version 1.1.3 or earlier are vulnerable. The attack requires a user account with contributor privileges or greater to create or edit posts and pages containing the button shortcode.

Risk and Exploitability

The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in current reports. The vulnerability is not listed in the CISA KEV catalog. The attack surface is limited to authenticated contributor-level access, but the exposed script can affect every site visitor who views the maliciously crafted page.

Generated by OpenCVE AI on April 22, 2026 at 04:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade e.nigma Buttons to a version that addresses the sanitization issue (the most recent release from the vendor).
  • Remove any existing button shortcodes that contain injected scripts from posts and pages.
  • Restrict contributor-level and higher roles to trusted users or modify the roles of accounts no longer needed.

Generated by OpenCVE AI on April 22, 2026 at 04:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19194 The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
History

Thu, 26 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 02:15:00 +0000

Type Values Removed Values Added
Description The e.nigma buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortcode in all versions up to, and including, 1.1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Title e.nigma buttons <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T16:51:14.193Z

Reserved: 2025-06-03T15:06:53.599Z

Link: CVE-2025-5535

cve-icon Vulnrichment

Updated: 2025-06-26T13:30:09.649Z

cve-icon NVD

Status : Deferred

Published: 2025-06-26T02:15:21.493

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-5535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-22T04:15:07Z

Weaknesses