Impact
The Simple Divi Shortcode plugin for WordPress contains a stored cross‑site scripting vulnerability in the showmodule shortcode. The plugin fails to sanitize or escape the 'id' attribute, allowing an attacker to embed arbitrary HTML and JavaScript that is stored in the page content. When a user opens a page containing the malicious shortcode, the injected script executes in that user's browser, potentially leaking cookies, hijacking the user session, or redirecting to malicious sites. The flaw can be leveraged to violate confidentiality and integrity of user data and to trick users into interacting fraudulent content.
Affected Systems
WordPress sites running the Simple Divi Shortcode plugin, specifically versions 1.2 or earlier. The affected plugin is distributed by creaweb2b and ships under the name Simple Divi Shortcode. No specific WordPress core version is required, but the vulnerability exists in the plugin's code irrespective of the underlying WordPress version.
Risk and Exploitability
The CVSS score of 6.4 classifies this issue as a moderate‑severity vulnerability. No EPSS score is available, but the flaw is not listed in the CISA KEV catalog. The vulnerability requires an authenticated attacker with contributor or higher privileges to inject malicious content, making it an insider or compromised‑admin threat. An attacker can browse to any post or page that contains the showmodule shortcode; once injected, all visitors to that page will run the payload. Environments lacking strict content security policies are particularly vulnerable, and the impact can be magnified if enabled shortcodes are widely used across the site.
OpenCVE Enrichment