Impact
The e.nigma Buttons plugin allows users with contributor-level or higher to embed a button shortcode. Because the plugin fails to validate or escape user supplied attributes, an attacker can store malicious JavaScript in the shortcode. When any visitor loads a page containing the contaminated button, the embedded script executes in the visitor’s browser.
Affected Systems
All WordPress installations running chemiker e.nigma Buttons version 1.1.3 or earlier are vulnerable. The attack requires a user account with contributor privileges or greater to create or edit posts and pages containing the button shortcode.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in current reports. The vulnerability is not listed in the CISA KEV catalog. The attack surface is limited to authenticated contributor-level access, but the exposed script can affect every site visitor who views the maliciously crafted page.
OpenCVE Enrichment
EUVD