Impact
The Zoomify embed for WP plugin contains a stored XSS vulnerability caused by an improper neutralization of input during web page generation. The flaw allows an attacker to persist malicious script code that will be executed in the browsers of any visitor viewing the affected content. This stored data is reflected directly into the page, enabling client‑side attacks such as script execution within the user’s session.
Affected Systems
The vulnerability impacts the WordPress plugin Zoomify embed for WP (zoom-image-shortcode) from any version prior to and including 1.5.2. The vendor is SdeWijs. No other versions are explicitly listed as affected.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk. The EPSS score of less than 1% suggests a very low probability of exploitation at present, and the issue is not listed in the CISA KEV catalog. The attack vector is most likely web‑based, requiring the ability to insert a malicious payload into the plugin’s input fields, which will then be rendered when the content is displayed.
OpenCVE Enrichment
EUVD