Impact
The Surbma | Infusionsoft Shortcode plugin for WordPress has a stored XSS flaw because the "account" and "id" attributes of the "infusionsoft-form" shortcode are concatenated directly into a <script> tag’s src attribute without proper sanitization. An attacker who is authenticated with contributor rights or higher can embed arbitrary JavaScript that executes whenever a user opens a page containing the malicious shortcode.
Affected Systems
Surbma, WordPress plugin Surbma | Infusionsoft Shortcode, affected versions include all releases up to and including 2.0.1.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated contributor or higher user, so it is not publicly exploitable. Once the malicious script is injected, it runs in the browser context of any visitor to the affected page, potentially allowing phishing, session hijacking, or defacement.
OpenCVE Enrichment