Impact
The Bootstrap Shortcode plugin contains a stored cross‑site scripting flaw in the `box` shortcode. Invalid attributes are not properly sanitized or escaped, allowing an authenticated user with Contributor level or higher to inject arbitrary JavaScript into the page content. Once injected, the script runs automatically whenever any visitor loads the affected page, resulting in a loss of confidentiality, integrity, and availability of the data displayed on the site.
Affected Systems
The vulnerability affects all releases of the Bootstrap Shortcode plugin version 1.0 and older. This includes installations that have not applied a patch or upgraded beyond the 1.0 release line.
Risk and Exploitability
The CVSS score of 6.4 indicates moderate severity. The EPSS score is not listed, and the vulnerability is not part of the CISA KEV catalog. The flaw requires the attacker to be authenticated as a Contributor or higher role, so the attack vector is local to the WordPress administration console rather than remote. Once an authenticated user injects the script, every subsequent visitor to the page will execute it, providing a persistent and widespread impact for site users.
OpenCVE Enrichment