Impact
The vulnerability allows an attacker who can log into the site with a contributor role or higher to insert malicious JavaScript code through the ‘button’ attribute of the logout‑url shortcode. Because the value is stored and later rendered without proper sanitization, the injected script will run in the browser context of any user who views a page containing the modified shortcode. This can lead to defacement, credential theft, or other client‑side attacks. The weakness is a classic stored XSS flaw, classified as CWE‑79.
Affected Systems
PeproDev Ultimate Profile Solutions for WordPress, versions 8.2.36 and earlier. The flaw exists in all releases up to and including 8.2.36, regardless of other plugins or themes installed.
Risk and Exploitability
The CVSS score of 6.4 places the vulnerability in the moderate range; no exploit probability data is available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access with contributor‑level capability or higher, meaning the threat is limited to users who have been granted such permissions within the WordPress installation. However, once an attacker gains that level of access, they can affect all other users of the site by injecting scripts that will run across all authenticated sessions. As the vulnerability is a stored XSS, it is readily exploitable if attackers can reach the shortcode interface, and no significant configuration or environmental restrictions are noted.
OpenCVE Enrichment