Impact
The Euro FxRef Currency Converter plugin allows authenticated users with contributor or higher privileges to insert content through the currency shortcode. Unsanitized shortcode attributes store content that is later rendered without proper escaping, leading to stored cross‑site scripting. A successful injection lets an attacker execute arbitrary scripts within the context of any user who views the affected page, potentially compromising credentials, session data, or delivering malware.
Affected Systems
WordPress sites running the Euro FxRef Currency Converter plugin by DKZR, versions up to and including 2.0.2.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access at the contributor level or higher, meaning the attacker must first obtain legitimate user credentials. Given the limited attack surface and low exploitation probability, the overall risk is moderate but should be mitigated promptly.
OpenCVE Enrichment
EUVD