Impact
The Snippet Shortcodes plugin for WordPress is vulnerable to a stored XSS flaw because it does not properly sanitize or escape the values supplied in shortcode attributes. This flaw allows an attacker who is authenticated with contributor‑level permissions or higher to inject malicious JavaScript that will execute in the browsers of any user who views the affected page. The impact is the non‑repudiation of arbitrary script execution and the potential for session hijacking, defacement, or downstream data theft. The weakness is identified as CWE‑79.
Affected Systems
Affecting the WordPress plugin "Snippet Shortcodes" produced by aliakro. All released versions up to and including 5.2.0 are vulnerable; any installation running 5.2.0 or earlier is at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.4, indicating a moderate severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet observed, but the presence of an authenticated attacker with contributor access greatly increases the risk. The likely attack vector is via the plugin’s handling of shortcode attributes during content rendering, and exploitation requires the attacker to have logged‑in access on the target site.
OpenCVE Enrichment