Impact
The vulnerability occurs in the Fleetwire Fleet Management plugin for WordPress and is caused by insufficient sanitization of user‑supplied attributes within the fleetwire_list shortcode. An attacker who has at least contributor‑level access can persistently inject arbitrary JavaScript, which will execute in the browsers of any user who views a page that contains the injected shortcode. This stored cross‑site scripting can be used to deface the site, steal credentials, or redirect users to malicious sites.
Affected Systems
All installations of the Fleetwire Fleet Management plugin for WordPress up to and including version 1.0.19 are affected. The plugin is deployed on WordPress sites, so any site that grants contributor‑level or higher privileges can be coerced into injecting scripts.
Risk and Exploitability
The CVSS base score is 6.4, indicating medium severity. The EPSS score is less than 1 %, showing a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog. The requirement for authenticated access restricts the attacker to those already possessing contributor‑level or higher rights, but the potential impact remains significant if exploited.
OpenCVE Enrichment
EUVD