Impact
A stored XSS flaw exists in the NextScripts Social Networks Auto‑Poster plugin through its `[nxs_fbembed]` shortcode. The plugin fails to properly sanitize or escape data stored in the `snapFB` post meta field, allowing a contributor‑level user to embed malicious scripts that will execute whenever a page containing the shortcode is viewed. This can lead to credential theft, defacement, session hijack, or other client‑side attacks against site visitors.
Affected Systems
The vulnerability affects the NextScripts Social Networks Auto‑Poster plugin for WordPress, all versions up to and including 4.4.6. Any WordPress site installing that plugin and providing Contributor or higher roles to users is at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. However, the attack requires only authenticated access with Contributor rights, a relatively low privilege level, and the user must manually insert the malicious shortcode. The flaw is exploit‑able server‑side, and the resulting script execution occurs client‑side when visitors load the infected page.
OpenCVE Enrichment