Impact
Unauthenticated Cross Site Scripting (XSS) in the WordPress URL Shortify plugin allows attackers to inject arbitrary JavaScript that executes in visitors’ browsers, posing a risk of client‑side compromise. The flaw arises from insufficient sanitization of user input and is classified under CWE‑79.
Affected Systems
KaizenCoders’ URL Shortify plugin version 2.5.0 or earlier, installed on WordPress sites, is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. An unauthenticated attacker can supply malicious input to the plugin’s functionality, resulting in the injection of arbitrary JavaScript that executes in site visitors’ browsers. While the exact downstream effects are not documented in the CVE entry, this client‑side execution can expose the site to potential compromise. Prompt remediation via patching is recommended to eliminate the risk.
OpenCVE Enrichment