Impact
The Muse.ai Skiv Video Embedding plugin for WordPress contains a stored XSS flaw that allows an authenticated user with contributor permissions or higher to inject arbitrary JavaScript into the plugin’s short‑code attributes. When another user views a page containing the compromised short‑code, the injected script runs under that user’s context, enabling defacement, credential theft, or session hijacking. The weakness stems from insufficient input sanitisation and lack of output escaping and is classified as CWE‑79.
Affected Systems
All WordPress installations running versions of the Muse.ai Skiv Video Embedding plugin up to and including 0.4 are affected. Users of older or unpatched installations should verify the plugin version and update as needed.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, but the EPSS score of less than 1% suggests that the likelihood of exploitation is very low in the current landscape. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated contributor‑level account and the ability to insert a short‑code into a page or post. Once the short‑code is stored, the attack becomes a classic stored XSS that can affect any visitor to the compromised page.
OpenCVE Enrichment
EUVD