Impact
The vulnerability stems from improper neutralization of input during web page generation, enabling a DOM‑based XSS flaw. An attacker can inject malicious scripts that run in a victim’s browser, potentially stealing session cookies, defacing content, or executing further client‑side attacks.
Affected Systems
The affected product is WordPress Penci Shortcodes & Performance by PenciDesign, versions up to and including 6.1. Any installation of the plugin at these versions is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, while the predicted probability of exploitation is very low. The flaw is not part of the CISA KEV list. Exploitation requires a user to visit a page served by an affected instance of the plugin, after which the attacker can inject arbitrary JavaScript. The attack vector is client‑side through the plugin’s shortcode handling (inferred from the description).
OpenCVE Enrichment