Impact
The vulnerability is a stored cross‑site scripting flaw that occurs when user‑supplied attributes in shortcode tags are not properly sanitized or escaped. It allows authenticated users with Contributor or higher permissions to inject malicious JavaScript which will run whenever any user views the affected page, potentially enabling session hijacking, defacement, or theft of sensitive data. This weakness is identified as CWE‑79.
Affected Systems
Affected products are the Biagiotti Core WordPress plugin from Mikado Themes. Versions up to and including 2.1.3 are vulnerable. Any site running these versions is at risk until a fix is applied.
Risk and Exploitability
The CVSS base score is 6.4, indicating a moderate severity. With an EPSS score of less than 1 % and no listing in CISA’s KEV catalog, exploitation is expected to be rare, but the requirement of authenticated Contributor access means internal users can mount the attack. The risk remains significant for sites that allow contributors to edit content or use shortcodes, as the flaw leads to arbitrary script execution on front‑end pages.
OpenCVE Enrichment
EUVD