Impact
Shortcodes Ultimate does not sanitize or escape the "su_slide_link" attachment metadata used by its carousel shortcode. An authenticated user with author or higher privileges can insert arbitrary JavaScript into this field. When a page containing the carousel loads, the injected script executes in the browsers of any visitor, enabling credential theft, defacement, or other malicious actions.
Affected Systems
WordPress sites running the Shortcodes Ultimate plugin by gn_themes, version 7.4.8 and older.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity. EPSS information is absent, so the likelihood of exploitation is uncertain. The vulnerability is not listed in CISA’s KEV. Exploitation requires authenticated access at author level or higher; the attack vector is local (user must be logged in). Once exploited, the impact is non‑disruptive but can compromise data and trust for all site visitors.
OpenCVE Enrichment