Impact
The vulnerable plugin allows an attacker to store arbitrary JavaScript in pages via the shortcode, leading to stored XSS. An injected script can then run in the context of the site’s visitors, enabling session hijacking, credential theft, or defacement. The weakness is a classic input‑validation failure, identified as CWE‑79, and it compromises the confidentiality and integrity of all users who view affected pages.
Affected Systems
WordPress sites that use the douglaskarr List Child Pages Shortcode plugin, versions from the earliest available up to and including 1.3.1. Site administrators who have not yet upgraded to a newer version are at risk.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw permits stored code to be executed in visitors’ browsers, any active site with the affected plugin could become a vector for phishing or credential theft if an attacker compromises the shortcode’s input storage.
OpenCVE Enrichment
EUVD