Impact
The Fancy Image Show WordPress plugin is vulnerable to stored cross‑site scripting that allows authenticated attackers with contributor or higher privileges to inject arbitrary JavaScript into pages via the plugin’s shortcode attributes. Once injected, the script executes whenever a user views the altered page, potentially enabling data theft, session hijacking, or defacement of the site for all visitors. No network-level exploit is required; the impact is confined to browsers rendering the compromised content.
Affected Systems
The vulnerability affects the Fancy Image Show plugin for WordPress, versions up to and including 9.1. Any site running one of these versions is susceptible unless the plugin has been updated to a fixed release.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. The attack requires authentication and contributor-level access, which limits initial compromise to users with elevated roles, but once exploitation succeeds the malicious script runs in every visitor’s browser. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not actively exploited at scale yet. Nevertheless, the ease of injection combined with the broad impact to page viewers warrants prompt remediation.
OpenCVE Enrichment