Impact
GBI To Print plugin for WordPress version 1.0 contains a stored cross‑site scripting flaw. The gbi_toprint_shortcode() function builds an HTML attribute from the raw 'div' shortcode argument without sanitization, allowing authenticated users with contributor or higher role to embed arbitrary JavaScript that will run in the context of any page containing the edited content. This can be used to hijack user sessions, deface sites, or exfiltrate data.
Affected Systems
Affected systems are WordPress installations that include the GBI To Print plugin, specifically version 1.0. The flaw exists wherever the faulty shortcode is used, regardless of theme or other plugins.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity, and the EPSS score is not available. The vulnerability is not currently listed in the CISA KEV catalog, but the lack of an EPSS value does not preclude potential exploitation. Attackers require authenticated access, typically via the WordPress admin panel, and must have contributor‑level privileges to edit content and insert the malicious shortcode.
OpenCVE Enrichment