Impact
The Modern Design Library plugin for WordPress contains a stored cross‑site scripting flaw in the ‘class’ parameter up through version 1.1.4. Authenticated users with Contributor‑level access or higher can inject arbitrary scripts that will run whenever a user opens a page containing the injected content, leading to client‑side code execution and potential data theft or session hijacking.
Affected Systems
Any WordPress site running the Modern Design Library plugin provided by butterflymedia, at or below version 1.1.4, is affected. The vulnerability applies to all installations where contributors have permission to edit or add shortcodes that include the vulnerable ‘class’ parameter.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of < 1% signals a low probability of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Attackers must be authenticated with at least Contributor rights; there are no additional prerequisites beyond the ability to edit or create shortcodes. Successful exploitation results in arbitrary script execution in the browsers of any site visitor who views the affected page, potentially compromising user sessions and data.
OpenCVE Enrichment
EUVD