Impact
The Embed Google Datastudio WordPress plugin contains a stored cross‑site scripting flaw caused by insufficient sanitization of attributes passed to the egds shortcode, allowing an authenticated contributor or higher to insert malicious script code into a page. When a user later views the page, the injected script executes in the context of the site, potentially enabling defacement, cookie theft, or phishing against page viewers.
Affected Systems
The vulnerability applies to all versions of the Embed Google Datastudio plugin up to and including 1.0.0; sites installing any of these releases are vulnerable.
Risk and Exploitability
With a CVSS score of 6.4 the flaw is considered moderate in severity, while an EPSS score of less than 1% indicates a low probability of exploitation at present. The plugin is not listed in the CISA KEV catalog. Attackers must be authenticated with at least contributor privileges to embed malicious code; subsequent exploitation occurs when even non‑privileged users view the affected page.
OpenCVE Enrichment
EUVD