Impact
The vulnerability resides in the Custom Twitter Feeds WordPress plugin and allows authenticated users with contributor‑level privileges or higher to insert arbitrary JavaScript into the page via the "buttoncolor" shortcode attribute. The input is not sufficiently sanitized or escaped before being stored, which means the script is saved in the database and executed in any browser that renders the affected page. This can lead to theft of session information, defacement, or execution of further malicious code by unsuspecting site visitors.
Affected Systems
All installations of the Custom Twitter Feeds plugin version 2.8.0 and earlier are vulnerable. The issue manifests when contributors or administrators can edit posts or widgets that use the plugin’s shortcode, especially when the legacy shortcode support option is enabled due to legacy feed configuration or legacy token usage. Typical WordPress sites that have this plugin and provide contributor access to the frontend are at risk.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of observed exploitation at this time; the vulnerability is not currently listed in the CISA KEV catalog. An attacker still could exploit the flaw by authenticated access to the WordPress backend, inserting a malicious shortcode in a page or post, which is then stored and served to all users. The impact is primarily a stored XSS that affects the confidentiality and integrity of user sessions and the availability of the site’s content to those users.
OpenCVE Enrichment