Impact
In the Shortcodely WordPress plugin the widget_area shortcode attribute is stored without adequate sanitization or escaping, allowing an authenticated user with contributor‑level access to inject malicious scripts into content. Those scripts execute whenever a user views the affected page, potentially enabling defacement, credential theft or other persistence attacks.
Affected Systems
The vendor patilswapnilv’s Shortcodely plugin for WordPress is impacted, with all releases up to and including version 1.0.1 vulnerable to exploited input. Site owners running these plugin versions and the widget_area shortcode are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates medium severity, and the vulnerability is not listed in the KEV catalog. Because exploitation requires authenticated contributor‑level privileges, attackers must first gain access to the WordPress backend; after injection the stored script executes for all subsequent visitors. With no EPSS data available the exploitation probability is uncertain, yet the potential user impact is significant due to persistent cross‑site scripting on content pages.
OpenCVE Enrichment