Impact
The Child Pages Card WordPress plugin before version 1.09 accepts shortcode attributes without sanitisation or escaping, allowing an attacker with a contributor role or higher to store malicious scripts in page content. When the page is rendered, the script executes in the browsers of all visitors, giving the attacker a stored Cross‑Site Scripting vector that satisfies CWE‑79.
Affected Systems
Any WordPress site that uses the Child Pages Card plugin prior to version 1.09 is vulnerable. The risk is limited to content that contains the plugin’s shortcodes and is managed by users with contributor-level permissions or higher. Sites that have already upgraded to 1.09 or later are not affected by this specific flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score remains below 1%. The stored XSS attack can affect every visitor to a page that includes the vulnerable shortcode. The vulnerability is not listed in CISA’s KEV catalog, implying limited known exploitation. Likely attack vectors involve a legitimate contributor inserting malicious attributes into the shortcode; the stored payload then persists until the plugin or content is removed. Given the scope of impact and the lack of mitigation measures, the risk remains high for affected installations until a patch is applied.
OpenCVE Enrichment