Impact
This vulnerability allows a malicious actor to inject arbitrary JavaScript that is stored in the WordPress Logo Showcase plugin. When an attacker supplies specially crafted input, it is rendered unfiltered on the site, enabling stored XSS. Because the payload persists, any visitor to the compromised pages would execute the injected script, potentially phishing for credentials, defacing content, or hijacking sessions.
Affected Systems
Themepoints Logo Showcase plugin (commonly known as Logo Showcase) for WordPress. All releases up to and including version 4.0.4 are vulnerable; versions newer than 4.0.4, such as 4.0.5, contain the fix.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, but the exploitation likelihood is unclear as EPSS data is not available. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to supply input through the plugin’s administrative interface, which typically necessitates an account with appropriate permissions. Once injected, the stored payload automatically executes in the browsers of any site visitor, producing a non‑trivial risk to confidentiality, integrity, and availability of the target.
OpenCVE Enrichment