Impact
The Surbma | Recent Comments Shortcode plugin for WordPress contains a stored cross‑site scripting flaw because it fails to sanitize user supplied attributes in the 'recent‑comments' shortcode. This allows an authenticated contributor or higher to inject arbitrary JavaScript that is stored in the content and will run in the browsers of any user who visits the page containing the shortcode. The resulting impact is script execution that can lead to session hijacking, defacement, or malware delivery.
Affected Systems
WordPress installations that have the Surbma | Recent Comments Shortcode plugin installed, on any version up to and including 2.0.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of <1% shows a very low probability of exploitation. The vulnerability is not yet cataloged in the CISA KEV list. Exploitation requires an authenticated user with contributor-level access or higher, so the attack vector is likely via the WordPress shortcode mechanism. The overall risk can be considered low to moderate given the limited attacker access requirement and low exploitation likelihood.
OpenCVE Enrichment
EUVD