Impact
The azurecurve BBCode plugin for WordPress is vulnerable to stored cross‑site scripting through the 'url' shortcode. The plugin fails to sanitize or escape attribute values supplied by a user, allowing an authenticated attacker with Contributor or higher privileges to inject arbitrary web scripts into content that will execute when any site visitor loads a page containing the shortcode. This flaw enables the attacker to run client‑side code in the browser context of unsuspecting users, potentially leading to session hijacking, credential theft, or defacement of the site.
Affected Systems
All installations of the azurecurve BBCode WordPress plugin through version 2.0.4 inclusive are affected. Any WordPress site that includes this plugin and has users with Contributor or higher roles can be used to exploit the vulnerability.
Risk and Exploitability
The CVSS v3 score of 6.4 indicates a moderate severity, and the EPSS score of less than 1% signals a very low probability of active exploitation. The plugin is not listed in the CISA KEV catalog. The flaw requires an attacker to be authenticated with at least Contributor access, and they must be able to edit or create posts that include the vulnerable shortcode. Once the malicious code is stored, it will affect all users who view the affected content, but exploitation depends on the attacker’s ability to gain the necessary role and create or modify posts.
OpenCVE Enrichment
EUVD