Impact
The TinyMCE shortcode Addon for WordPress allows an attacker with contributor or higher privileges to insert arbitrary JavaScript through the 'btnrel' shortcode attribute. When a page containing the malicious shortcode is viewed, the script runs in the victim’s browser, potentially exposing or manipulating data that the user has access to.
Affected Systems
The vulnerability exists in the TinyMCE shortcode Addon produced by 360crest. All released versions up to and including 1.0.0 are affected on WordPress sites that install the plugin.
Risk and Exploitability
The flaw carries a CVSS score of 6.4, indicating moderate severity. EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, so current exploitation prevalence is unknown. Attackers must have authenticated contributor access to create the malicious content, but once the shortcode is stored the embedded script executes for every user who opens the affected page. No publicly disclosed exploit is known, however the stored nature of the payload makes exploitation straightforward once a user has the required permissions.
OpenCVE Enrichment