Impact
The vulnerability is an improper neutralization of user input during web page generation, allowing malicious scripts to run in the browsers of visitors. This standard input validation flaw, identified as CWE‑79, enables DOM‑based cross‑site scripting that can compromise the confidentiality and session integrity of users who view affected content.
Affected Systems
The affected system is the WordPress plugin ‘Shortcodes and extra features for Phlox theme’ developed by Averta LTD. All installations of the plugin up through version 2.17.16 are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 demonstrates moderate severity, while the EPSS score of less than 1 % indicates a very low but nonzero exploitation probability. The likely attack vector is DOM‑based XSS page rendered by the plugin with unsanitized input. An attacker who can configure the plugin could embed malicious code, and any user who views the affected page would execute the payload.
OpenCVE Enrichment