Impact
The Spotify Embed Creator plugin for WordPress is vulnerable to stored cross‑site scripting through the plugin’s ‘spotify’ shortcode. Insufficient input sanitization and output escaping on user‑supplied attributes allow attackers with contributor‑level access to inject arbitrary web scripts. When a victim views a page containing the malicious shortcode, the injected scripts are executed in the victim’s browser, potentially leading to data theft or session hijack.
Affected Systems
WordPress plugin Spotify Embed Creator, versions 1.0.5 and earlier. Any WordPress site running a vulnerable instance of this plugin is affected.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity vulnerability. The EPSS score of less than 1% suggests the likelihood of exploitation is low at this time, and the vulnerability is not listed in the CISA KEV catalog. Attackers must first authenticate to the WordPress site with contributor or higher privileges to inject the malicious shortcode, after which the stored scripts will run whenever a user opens the affected page. The impact is primarily the ability to execute arbitrary code in the context of the site’s front‑end, which can be leveraged for phishing, credential theft, or other malicious activity.
OpenCVE Enrichment
EUVD