Impact
The Pods plugin for WordPress contains a stored XSS flaw in the ‘not_found’ shortcode attribute. Because input is not sanitized or escaped, an authenticated user with contributor-level or higher privileges can embed arbitrary JavaScript into that attribute. When a page containing the injected shortcode is rendered, the stored script executes in the browsers of all visitors to that page.
Affected Systems
The issue affects the Pods – Custom Content Types and Fields plugin for WordPress, developed by sc0ttkclark. All releases up to and including version 3.3.9.1 are vulnerable. Any WordPress site running one of those versions and allowing contributor-level or higher users to add or edit content through Pods is susceptible.
Risk and Exploitability
The CVSS base score of 6.4 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated account with contributor role or higher. Once such credentials are available, adding malicious content through the plugin’s shortcode interface is straightforward, leading to stored payload execution on the site for all users who view the affected page.
OpenCVE Enrichment