Impact
The DeMomentSomTres Shortcodes plugin for WordPress contains a stored cross‑site scripting flaw in the callout shortcode when the width and align attributes are used. The plugin concatenates these attribute values directly into a style attribute without sanitization or escaping, enabling authenticated users with contributor or higher privileges to embed arbitrary JavaScript in published content. When any visitor loads a page that contains the malicious shortcode, the injected script executes in that visitor’s browser context, which can lead to session hijacking, defacement, or further exploitation.
Affected Systems
This vulnerability affects all releases of the Marcqueralt DeMomentSomTres Shortcodes WordPress plugin up to and including version 1.1.1. Any WordPress site that hosts a vulnerable version and has users with contributor or greater access is susceptible.
Risk and Exploitability
The CVSS score of 6.4 classifies this as a moderate severity flaw. Exploitation requires an authenticated contributor or higher, so an attacker must first obtain valid site credentials or elevated permissions. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation yet. Nevertheless, once the attacker can insert the payload, all visitors to the affected page become potential victims, making the risk significant for production sites that use the plugin.
OpenCVE Enrichment