Impact
The Child Pages Card WordPress plugin before version 1.09 accepts shortcode attributes without sanitisation or escaping, allowing an attacker with a contributor role or higher to store malicious scripts in page content. When the page is rendered, the script executes in the browsers of all visitors, giving the attacker a stored Cross‑Site Scripting vector that satisfies CWE‑79. The flaw permits complete compromise of confidentiality and integrity for site users, while also allowing the attacker to inject further payloads.
Affected Systems
Any WordPress site that uses the Child Pages Card plugin prior to version 1.09 is vulnerable. The risk is limited to content that contains the plugin’s shortcodes and is managed by users with contributor-level permissions or higher. Sites that have already upgraded to 1.09 or later are not affected by this specific flaw.
Risk and Exploitability
Because the CVSS and EPSS scores are not available, the quantitative severity is unknown; however, the stored XSS attack can affect every visitor to a page that includes the vulnerable shortcode. The vulnerability is not listed in CISA’s KEV catalog, implying limited known exploitation. Likely attack vectors involve a legitimate contributor inserting malicious attributes into the shortcode; the stored payload then persists until the plugin or content is removed. Given the scope of impact and the lack of mitigation measures, the risk remains high for affected installations until a patch is applied.
OpenCVE Enrichment