Impact
The Global Body Mass Index Calculator plugin for WordPress includes a stored cross‑site scripting flaw that arises from insufficient sanitization of shortcode attributes. Authenticated users with contributor or higher privileges can insert malicious payloads into attributes such as height, width, or title. When the shortcode is rendered, the payload is injected unescaped into the page context, allowing attackers to run arbitrary JavaScript against any visitor of the affected page.
Affected Systems
The vulnerability affects the Global Body Mass Index Calculator plugin for all WordPress installations running versions up to and including 1.2. No other product versions are known to be vulnerable, and the flaw persists until a fixed release is deployed.
Risk and Exploitability
The CVSS base score of 6.4 indicates a medium severity risk, and the exploit requires authenticated contributor access, limiting the potential attacker set. Because no EPSS value is available and the issue is not listed in the CISA KEV catalog, the current risk remains moderate, but the ability to compromise site occupants on page view makes timely remediation advisable.
OpenCVE Enrichment