Impact
The vulnerability stems from improper sanitization of contributor input in the Wufoo Shortcode plugin. Malicious JavaScript can be introduced via the shortcode editor, and it is rendered without escaping, creating an XSS flaw. An attacker who can supply such input could deface content, steal session cookies, or redirect users to malicious sites.
Affected Systems
WordPress sites running Wufoo Shortcode version 1.55 or earlier, distributed by wronganswersonly:Wufoo Shortcode. No specific WordPress core version is mentioned in the advisory.
Risk and Exploitability
The CVSS score of 6.5 denotes a moderate severity. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the flaw is of moderate risk and is not listed in the CISA KEV catalog. Attackers can exploit this from any contributor interface without needing elevated privileges, provided they can submit a malicious shortcode.
OpenCVE Enrichment