Impact
The vulnerability is a stored cross‑site scripting flaw in the "rem_video" shortcode of the Responsive Video Embedder plugin. User‑supplied shortcode attributes (id and list) are concatenated directly into an iframe src attribute without any sanitization or escaping. An authenticated contributor or higher can insert malicious JavaScript that will run in every browser that renders the affected page, leading to defacement, credential theft, or other malicious actions.
Affected Systems
The flaw affects the Responsive Video Embedder plugin for WordPress, versions 0.1 and earlier. Users running any of these versions are susceptible. The plugin is distributed by esiteq.
Risk and Exploitability
The CVSS score is 6.4, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA KEV. Exploitation requires that the attacker holds contributor‑level or higher access to add or edit content, after which the malicious script will be stored and executed on every page load that contains the shortcode. The moderate CVSS score combined with the need for authenticated access suggests that the risk is significant for sites with many contributors.
OpenCVE Enrichment