Impact
The Shortcodes Ultimate plugin contains a stored XSS flaw in the su_box shortcode. Because the plugin does not sanitize or escape user‑supplied attributes, an authenticated user with contributor permissions can store arbitrary JavaScript in the database. The script is rendered and executed during page load for any visitor who views a page containing the malicious shortcode.
Affected Systems
The flaw affects the WordPress plugin Shortcodes Ultimate released by gn_themes. All versions up to and including 7.4.9 are vulnerable.
Risk and Exploitability
The CVSS score of 6.4 classifies this issue as moderate. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so no active exploitation has been reported. Exploitation requires only authenticated contributor access, a level of permission often granted to content authors. Once a malicious script is stored, it remains until the content is modified or the shortcode is removed, potentially affecting all users who access the compromised page.
OpenCVE Enrichment