Impact
The CM CSS Columns plugin for WordPress suffers from a stored Cross‑Site Scripting vulnerability that allows an authenticated user with Contributor access or higher to inject malicious scripts via the 'tag' shortcode attribute. The attacker can embed any JavaScript that will run in the context of all users viewing the affected page, potentially leaking credentials, defacing the site, or coercing users into unwanted actions.
Affected Systems
Codemacher’s CM CSS Columns WordPress plugin, any instance of the plugin installed with version 1.2.1 or earlier. All releases up to and including 1.2.1 contain the flaw. No specific build numbers are listed beyond the upper bound of 1.2.1.
Risk and Exploitability
The vulnerability receives a CVSS base score of 6.4, indicating moderate severity, and an EPSS score of less than 1 %, suggesting a low probability of exploitation at this time. It is not yet listed in the CISA KEV catalog. Attackers must first authenticate as a Contributor or higher and then supply a crafted 'tag' attribute value in a shortcode. Once injected, the malicious code executes on every page load for any user who views the content, making the attack highly impactful within the boundaries of script execution and data theft.
OpenCVE Enrichment