Impact
The vulnerability allows an authenticated user with contributor‑level or higher permissions to inject arbitrary JavaScript into pages through the plugin's 'rpwe' shortcode. Unsanitized attributes result in a stored cross‑site scripting flaw, meaning the malicious code persists and executes each time the compromised page is accessed. Such injected scripts can steal session cookies, deface content, or redirect users, leading to confidentiality, integrity, or availability impacts.
Affected Systems
WordPress installations that have the Recent Posts Widget Extended plugin from themejunkie with version 2.0.2 or earlier. No other products or versions are impacted according to the CNA data.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers must be authenticated with at least contributor privileges to embed the malicious shortcode; the flaw is most likely exploited through authenticated content editing on the site, making it a remote attack vector that requires network access to the website.
OpenCVE Enrichment
EUVD