Impact
The Enhanced BibliPlug WordPress plugin is vulnerable to stored cross‑site scripting via its bibliplug_authors shortcode. The plugin does not properly sanitize or escape user‑supplied attributes, allowing an authenticated user with contributor or higher role to embed arbitrary JavaScript that is executed whenever the affected page is viewed. This flaw is a classic CWE‑79 type input handling weakness.
Affected Systems
All releases of the Enhanced BibliPlug WordPress plugin up to and including version 1.3.8 are affected. Sites that host any of those versions and permit contributors or higher roles to insert content using the bibliplug_authors shortcode are vulnerable.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score of less than 1% suggests a low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access at the contributor level or higher; once a malicious script is stored via the shortcode, it is delivered to all users who visit the affected page.
OpenCVE Enrichment
EUVD