Impact
The Surbma Yoast SEO Breadcrumb Shortcode WordPress plugin versions 1.2 and earlier contains an input validation flaw that fails to escape data supplied through its shortcode, allowing the execution of arbitrary JavaScript when browsers render a page containing the shortcode. This flaw can lead to client‑side script injection that may compromise user data or interfere with site functionality.
Affected Systems
Any WordPress site running the Surbma Yoast SEO Breadcrumb Shortcode plugin at version 1.2 or older is affected. Sites that enable users such as contributors or editors to create or edit content that includes the shortcode present an attack surface for the flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability, while the EPSS score of < 1% suggests a very low likelihood of exploitation. The plugin is not listed in CISA’s KEV catalog, implying no widespread exploitation has been reported. The primary attack vector is remote, and it requires the ability to inject or edit content with the shortcode – a privilege level that is inferred from the plugin’s functionality but not explicitly specified in the CVE description.
OpenCVE Enrichment