Impact
The Drive Folder Embedder plugin for WordPress contains a stored cross‑site scripting flaw that is triggered by the tablecssclass parameter. When an authenticated user with at least Contributor privileges supplies malicious code to that parameter, the plugin stores it and later outputs it unescaped within page markup, causing any visiting user to execute the injected script. This can lead to session theft, defacement, or malicious content delivery for all users who view the affected pages.
Affected Systems
The vulnerability afflicts WordPress sites running the Drive Folder Embedder add‑on from azumbro. All releases up to and including version 1.1.0 are affected; any site that has not upgraded beyond that threshold is at risk. The issue arises regardless of the WordPress core version, but only those installations that keep the plugin enabled are vulnerable.
Risk and Exploitability
The CVSS rating is 6.4, placing the flaw in the medium‑to‑high range. The EPSS score is reported as less than 1 %, suggesting that exploitation is currently rare but still possible. The vulnerability is not listed in CISA’s KEV catalog, so there is no active critical exploitation reported. Attackers would need legitimate Contributor‑level credentials to create the payload, so the risk is largely confined to trusted users or compromised accounts. Nevertheless, because the injected script runs in the context of ordinary visitors, any authorizing role can introduce downstream threats.
OpenCVE Enrichment
EUVD