Impact
The WeedMaps Menu for WordPress plugin has a stored cross‑site scripting vulnerability in the weedmaps_menu shortcode. The plugin does not properly sanitize input or escape output for attributes supplied by users. This oversight lets an attacker with contributor‑level or higher WordPress access inject arbitrary scripts that are stored in the page content and executed whenever a visitor loads the affected page. The injected scripts can steal cookies, modify page content, or redirect users, thereby compromising the confidentiality and integrity of users’ information.
Affected Systems
All installations of the WeedMaps Menu for WordPress plugin up to and including version 1.2.0 are affected. The vendor is bmoredrew and the product name is WeedMaps Menu for WordPress. Any WordPress site with this plugin and users holding contributor, editor or administrator roles is vulnerable.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. The EPSS score is less than 1%, meaning exploitation is currently unlikely, and the vulnerability is not listed in CISA’s KEV catalog. The attacker must first obtain authenticated access at the contributor level or higher; however, once the malicious payload is stored it can impact all visitors who view the affected page. If sensitive data is displayed on such pages, the potential impact is significant, but the attack vector is confined to authenticated web sessions.
OpenCVE Enrichment
EUVD