Impact
This vulnerability arises from insufficient input sanitization and output escaping in the display_productive_breadcrumb shortcode of the Productive Style WordPress plugin. Contributed or higher‑privileged users can embed arbitrary scripts within shortcode attributes, which are then stored in the database and rendered on any page that uses the shortcode. This exploitation provides stored Cross‑Site Scripting (CWE‑79), allowing attackers to execute scripts in the browsers of all visitors to the affected page, potentially leading to session hijacking or content injection.
Affected Systems
The issue affects the Productive Style – Optimisations & Content Publishing Support plugin from Productiveminds, specifically all releases up to and including version 1.1.23. WordPress sites running a vulnerable version of the plugin are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation. The plugin is not listed in the CISA KEV catalog. Exploitation requires a contributor‑level or higher authenticated user to inject the malicious shortcode, after which any visitor who loads the affected page will execute the script. Because the attacker needs legitimate credentials to stage the payload, the overall risk is moderate but the real‑world impact depends on the availability of trusted contributors with sufficient privileges.
OpenCVE Enrichment
EUVD