Impact
The GC Social Wall plugin for WordPress is vulnerable to stored cross‑site scripting because the attributes of the gc_social_wall shortcode are not properly sanitized or escaped. An attacker who has at least contributor access can inject arbitrary JavaScript into the shortcode’s attributes, which is then stored in the database and executed whenever any user views a page containing that shortcode. This client‑side code execution can be used for phishing, cookie theft, defacement or further exploitation of the site’s users. The weakness is a classic stored XSS (CWE‑79).
Affected Systems
The vulnerable product is the GC Social Wall plugin from Guriev Creative. Versions up to and including 1.15 are affected, whereas any later revision is presumed fixed.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating medium severity. EPSS is less than 1 %, suggesting a low likelihood of exploitation at present, and the issue is not listed in the CISA KEV catalog. Exploitation requires an authenticated contributor or higher account to create or edit content that utilizes the gc_social_wall shortcode. Once a malicious payload is inserted, every visitor to the affected page will execute the injected script. The attack vector is thus web‑based content editing within the WordPress administration interface.
OpenCVE Enrichment
EUVD