Impact
The vulnerability exists in the myCred Points Management System plugin for WordPress, affecting all versions up to and including 3.2.4. The "wrapper" shortcode attribute accepts input that is not properly sanitized or escaped, allowing an attacker with contributor-level or higher authentication to store arbitrary JavaScript in content. Once stored, the script is rendered in every page that includes the shortcode, which executes in the browsers of any visitor to that page. The vulnerability enables the attacker to insert client‑side code that can manipulate the page or carry out malicious actions in the context of the visitor, thereby compromising the integrity of the content delivered. The weakness is classified as CWE‑79, an input validation failure with missing output encoding.
Affected Systems
All installations of the WordPress myCred Points Management System plugin up to and including version 3.2.4 are affected. The plugin is employed on WordPress sites that include the Sell Content addon where the "wrapper" shortcode is available. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The attack requires the attacker to first obtain contributor or higher authentication on the WordPress site, so it is not a purely remote exploitation. EPSS is not available, so no current exploitation statistics are provided. The vulnerability is not listed in the CISA KEV catalog. Because the exploit stores scripts in the content, a site administrator who has not yet applied the fix can be compromised once an attacker gains contributor access.
OpenCVE Enrichment