Impact
The SlideShowPro SC plugin for WordPress allows authenticated users with contributor or higher privileges to inject arbitrary scripts through the ‘slideShowProSC’ shortcode attribute. The plugin does not properly sanitize or escape the supplied ‘album’ attribute before it is stored, resulting in stored XSS. When a page containing the shortcode is loaded, the malicious script executes in the victim’s browser, potentially enabling cookie theft, session hijacking, or website defacement. The flaw is a classic example of insufficient input sanitization and output escaping, classified as CWE‑79.
Affected Systems
This vulnerability is present in all releases of SlideShowPro SC up to and including version 1.0.2. The impacted vendor is luetkemj, and the plugin is used on WordPress sites that assign contributor or higher roles to users. Any site that installs this plugin and permits those roles to add or edit content is susceptible.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. Exploitation requires authenticated access with contributor or higher privileges; no public exploit is documented and the EPSS score is unavailable. The flaw is not listed in CISA’s KEV catalog. Consequently, while the attack likelihood appears low, the potential impact on confidentiality, integrity, and availability is significant, warranting prompt remediation.
OpenCVE Enrichment