Impact
This vulnerability is a stored Cross‑Site Scripting flaw in the ThemeNectar Salient Shortcodes plugin. Unsanitized user‑supplied content that contains JavaScript can be persisted in the database and served to all visitors, allowing an attacker to execute arbitrary scripts in the browsers of site users. Such scripts may perform credential theft, session hijacking, defacement or drive malicious payloads, compromising confidentiality, integrity, and availability of the web application.
Affected Systems
The vulnerability affects the ThemeNectar Salient Shortcodes WordPress plugin versions up to and including 1.5.4. Users running any of these versions on their WordPress sites are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the vulnerability is not catalogued in the CISA KEV list. Attackers would exploit this via the content creation interface, embedding malicious JavaScript that is then rendered when other users view the affected content. Because the payload is stored, anyone who can edit or add content could deploy it, making the risk contingent on the privilege level of the attack vector.
OpenCVE Enrichment