Impact
The Simple Football Scoreboard plugin for WordPress contains a stored cross‑site scripting flaw in its shortcode attributes. An attacker who can authenticate to the site with Contributor or higher privileges can submit malicious code that is then saved and served to anyone who views a page containing the shortcode. The injected script will be executed in the browsers of all visitors to that page, enabling session hijacking, defacement, phishing, or other client‑side attacks.
Affected Systems
The vulnerability affects the dogrow Simple Football Scoreboard plugin in all released versions up to and including 1.0. No newer versions are listed as affected.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity. EPSS information is unavailable, and the flaw is not included in CISA’s Known Exploited Vulnerabilities catalog. Because the flaw requires authenticated access at the Contributor level, the likelihood of exploitation depends on the site’s role management. If a Contributor can edit posts or pages that use the shortcode, an attacker can inject arbitrary scripts; victims are compromised whenever they load the affected content.
OpenCVE Enrichment