Impact
The WP Highlight Box plugin for WordPress, in versions up to 1.0, fails to escape certain shortcode attributes before rendering them on a page. This flaw allows an attacker with the Contributor role or higher to insert malicious JavaScript that is stored and later executed when any visitor views the affected content. Stored Cross‑Site Scripting can lead to session hijacking, defacement, or delivery of malware to site visitors.
Affected Systems
WordPress installations that have the WP Highlight Box plugin installed with version 1.0 or earlier are affected. The vulnerability manifests when the highlight‑box shortcode is used on a public post or page, allowing a contributor or higher user to embed unsanitized attributes. No specific operating system or server platform constraints are noted in the advisory.
Risk and Exploitability
The CVSS score of 6.8 classifies the flaw as moderate severity. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that a contributor or higher user injects a malicious highlight‑box shortcode into a publicly viewable page, causing stored XSS for any visitor. While the overall risk remains lower due to the modest EPSS, the stored XSS remains a serious threat for sites that still grant contributors this capability, especially if the content is publicly displayed.
OpenCVE Enrichment