Impact
The Extra Settings for RocketChat WordPress plugin contains a stored cross‑site scripting vulnerability. The attacker can supply arbitrary content in the 'title' attribute of the 'rocketchat' shortcode. Because the plugin concatenates this value directly into HTML output without sanitization or escaping, the stored payload will execute in the browsers of any user who views a page that includes the shortcode.
Affected Systems
WordPress installations that employ the andrewabarber:Extra Settings for RocketChat plugin at version 0.1 or earlier and that allow contributors or higher roles to edit posts containing the 'rocketchat' shortcode are affected. The flaw is exploitable only on sites where the shortcode is enabled and where an attacker holds sufficient WordPress write permissions.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating moderate to high severity. EPSS data is not available and the flaw is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. An attacker must have at least contributor privileges to inject malicious content; upon publishing the shortcode, the script will run in the browsers of any site visitor.
OpenCVE Enrichment