Impact
The ZeM STL WordPress plugin contains a stored cross‑site scripting flaw that allows authenticated users with Contributor-level access to embed malicious scripts in posts via the [zemstl] shortcode attributes (url, color, bgcolor). The attacker can inject code that will execute for all users who view the affected page, compromising the confidentiality and integrity of the site’s content. This weakness is classified as CWE‑79 and the publicly available CVSS score of 6.4 indicates a medium severity vulnerability.
Affected Systems
The vulnerability affects all installations of the ZeM STL plugin version 1.0 and any prior release. Site owners using this plugin on their WordPress installations should verify whether they are running a vulnerable version.
Risk and Exploitability
The stored XSS flaw is exploitable only after the attacker has gained at least Contributor permission to edit or create posts. The malicious code is stored in the database and will execute for any visitor to the affected page. With the CVSS score of 6.4, the vulnerability is classified as medium severity. No EPSS estimate is available and the vulnerability is not listed in KEV. The risk is moderate due to the required privileged role, but the impact can affect all users who view the vulnerable content.
OpenCVE Enrichment