Impact
The vulnerability exists in the WP Composer plugin’s 'pbwp_raw_shortcode', which decodes Base64-encoded content and outputs it directly without sanitization. An authenticated attacker with Contributor level or higher can insert malicious JavaScript into a page or post. When any visitor loads the page, the injected script runs in the viewer’s browser, allowing the attacker to steal session cookies, perform phishing, or modify page content. The weakness is a stored XSS vulnerability (CWE-79).
Affected Systems
WP Composer – The Easiest Page Builder, all versions up to and including 1.0.5. Contributors and higher roles are required to exploit the flaw.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of immediate exploitation. The plugin is not yet listed in the CISA KEV catalog. Attackers must first authenticate as a Contributor or higher and embed a Base64-encoded payload in the shortcode; the injected code then executes automatically for any site visitor, potentially affecting all users who view the compromised page.
OpenCVE Enrichment