Impact
The Content Slideshow plugin for WordPress stores malicious JavaScript injected through shortcode attributes because the input is not adequately sanitized and the output is not properly escaped. An attacker who can authenticate with contributor-level privileges or higher can deliver arbitrary scripts that will execute in the browser of any user who views a page containing the affected shortcode.
Affected Systems
All versions of the Content Slideshow plugin up to and including 2.4.1 installed on any WordPress site are affected. The vulnerability is present in every build of the plugin up to this release.
Risk and Exploitability
The vulnerability has a CVSS score of 6.4, indicating medium severity. EPSS data are not available, and the flaw is not listed in the CISA KEV catalog. Because the attack requires authenticated contributor+ access, the exploitability is limited to users who already have elevated privileges, but once injected, the script runs for all other site visitors. The risk remains moderate; it is advisable to address the issue promptly rather than wait for a public exploit.
OpenCVE Enrichment