Impact
The vulnerability is an insufficiently sanitized attribute in a WordPress shortcode that concatenates user‑supplied data directly into an inline style block, allowing an authenticated contributor or higher to store malicious JavaScript. When the affected page is loaded, any visitor’s browser executes the injected script, making it possible to steal credentials, deface content, or hijack user sessions. The weakness is a classic stored XSS flaw with a moderate negative score of 6.4 on the CVSS scale.
Affected Systems
The affected product is the SKT Skill Bar plugin developed by sonalsinha21 for WordPress, specifically all releases that are version 2.6 or earlier. No other vendors or products are listed as impacted.
Risk and Exploitability
This stored XSS is only accessible to authenticated users with Contributor or higher privileges, meaning site administrators can deliberately save malicious content. While it does not provide remote code execution on the server, it can hijack any user who views the compromised page. The CVSS score of 6.4 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need legitimate WordPress credentials to inject the payload, after which every visitor of the edited page becomes a target.
OpenCVE Enrichment