Impact
Stored Cross‑Site Scripting (CWE‑79) occurs when the slideshow parameter is not properly sanitized or escaped. An attacker who has Contributor‑level access can embed malicious scripts that run automatically for any visitor who views a page containing the injected slideshow. This can lead to data theft, session hijacking, or site defacement.
Affected Systems
The Simple Featured Image plugin, authored by jdegayojr, is affected in all releases up to and including version 1.3.1 on WordPress sites. Users running these versions should be aware that any page rendering the slideshow shortcode is vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 6.4 indicates moderate severity, and the EPSS value of less than 1% suggests a low likelihood of widespread exploitation at this time. The vulnerability is not included in the CISA KEV catalog, and the attack requires authenticated access with Contributor or higher roles, which limits the attack surface but still poses a significant risk when such accounts exist.
OpenCVE Enrichment
EUVD