Impact
The Unify plugin for WordPress contains a stored XSS vulnerability in the unify_checkout shortcode. Insufficient sanitization and escaping of user‑supplied attributes allows an authenticated contributor or higher to inject arbitrary JavaScript that executes on any page load, enabling session hijacking, defacement, or credential theft.
Affected Systems
All versions of the Unify plugin up to and including 3.4.7 are affected. The plugin is provided by CodeClouds, and the vulnerability resides in the use of the unify_checkout shortcode. Versions 3.4.8 and later include the fix.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation. The vulnerability is currently not listed in CISA’s KEV catalog. Exploitation requires contributor-level access or higher, so the attack surface is limited to users with those privileges, but once in place the injected script runs for all site visitors.
OpenCVE Enrichment
EUVD