Impact
The InteractiveCalculator for WordPress plugin is vulnerable to stored Cross‑Site Scripting due to insufficient sanitization of the 'id' attribute in its shortcode. Authenticated users with contributor access and higher can inject arbitrary JavaScript that will run for any visitor to a page containing the shortcode. This allows attackers to deface content, steal session cookies, or launch phishing attacks against site users, potentially compromising confidentiality, integrity, and availability of the website’s users and data.
Affected Systems
WordPress sites running InteractiveCalculator for WordPress plugin versions 1.0.3 or earlier are affected. The vulnerability exists in all releases up to and including 1.0.3. Sites using newer plugin releases are not impacted.
Risk and Exploitability
The CVSS score of 6.4 classifies this flaw as a moderate severity issue. The EPSS score of less than 1% indicates that the likelihood of exploitation in the wild is very low as of the last assessment. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires authenticated access with contributor privileges, implying that the attack surface is limited to sites where such users exist. Once injected, the malicious script executes on every user visit to the affected page, making the damage immediate and pervasive.
OpenCVE Enrichment