Impact
The vulnerability allows an authenticated author or higher to inject arbitrary JavaScript into pages via the emd_mb_meta shortcode. The plugin fails to escape attachment titles for the image field, letting the raw post_title appear in a title attribute without sanitization. An attacker can embed malicious scripts that will execute whenever any user views a page containing the shortcode, enabling phishing, cookie theft, defacement, or exploitation of other XSS vectors.
Affected Systems
The issue exists in the Video Gallery – YouTube Gallery, Playlist & Video Grid WordPress plugin produced by emarket‑design and affects all releases up to and including version 4.0.4. It is relevant for sites running the plugin on any WordPress installation where users can upload attachments and use the emd_mb_meta shortcode.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity with a medium exploitation likelihood. The EPSS is not listed, but the vulnerability is not in the CISA KEV catalog. Attackers need a user account with author privileges (or higher) and the ability to upload files and create shortcodes. Once the payload is embedded, it is stored and delivered to all site visitors, making the threat significant for any public-facing website that trusts author-level users.
OpenCVE Enrichment