Impact
The Easy Waveform Player plugin for WordPress contains a stored cross‑site scripting flaw caused by insufficient sanitization and output escaping in the shortcode_easywaveformplayer() function. An authenticated attacker with Contributor‑level or higher privileges can embed arbitrary JavaScript into posts or pages. When a user visits a page that includes the injected shortcode, the attacker’s script executes in that user’s browser, potentially resulting in session hijacking, defacement, or execution of additional malicious payloads.
Affected Systems
The flaw impacts the Easy Waveform Player plugin by tymotey. All releases up to and including version 1.2.2 are vulnerable. Administrators should verify whether the site is running one of these affected versions and plan to upgrade to a fixed release once it becomes available, or otherwise restrict the use of the shortcode for privileged users.
Risk and Exploitability
According to the CVSS base score of 6.4, the vulnerability presents a moderate level of risk. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating limited evidence of exploitation to date. The attack requires an authenticated user with Contributor or higher permissions, so the risk is confined to environments where such roles exist. In the absence of a publicly released fix, mitigating measures should focus on restricting shortcode usage by privileged users and implementing defensive controls such as a strict Content Security Policy.
OpenCVE Enrichment