Impact
The vulnerability arises from insufficient sanitization of the 'width' and 'height' attributes supplied to the BitForm shortcode, allowing an authenticated WordPress contributor or higher to inject malicious scripts that are rendered inside an iframe's style attribute. When users view the affected page, the injected code executes in their browsers, enabling the attacker to steal session cookies, deface content, or redirect users. This weakness falls under the input validation domain (CWE-79).
Affected Systems
WordPress sites using the BitForm plugin version 1.1.0 or earlier are affected. The issue exists regardless of the installed WordPress core version and requires contributor-level or higher credentials to exploit. The plugin's shortcode features are relevant to any page or post that includes the [bitform] tag.
Risk and Exploitability
The CVSS score of 6.4 indicates a medium severity vulnerability. No EPSS data is available, and the vulnerability is not included in the CISA KEV catalog, suggesting limited public exploit activity. However, the attack vector is local and requires only contributor-level access, which is common for many site users, so the overall risk to sites with many contributors remains significant.
OpenCVE Enrichment