Impact
The Video Onclick plugin for WordPress contains stored XSS vulnerabilities triggered by the youtube shortcode. All released versions up through 0.4.7 process user‑supplied shortcode attributes without proper sanitization and escaping. Authenticated users who hold contributor privilege or higher can inject javascript into the shortcode content, which is then persisted and executed whenever any site visitor loads the affected page. This flaw permits attackers to deface user interfaces, steal session cookies, or perform other malicious actions within the context of the victim’s browser.
Affected Systems
Vendors and products affected are WordPress installations running the Video Onclick plugin versions up to and including 0.4.7. Any site using this plugin, regardless of the rest of the WordPress core or theme configuration, is vulnerable if the contributor or higher role is granted by an attacker.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, and the EPSS estimate of less than 1% reflects a low probability of exploitation in the wild. The vulnerability is not yet recorded in the CISA KEV catalog. An attacker can exploit this defect by simply adding malicious content via the shortcode editor; no additional network access or privilege escalation beyond contributor level is required. Once injected, scripts run in the context of all page viewers, turning each page visit into a potential vector for further compromise.
OpenCVE Enrichment