6.4
CVSSv3

CVE-2025-1559

CVSSv4: NA | CVSSv3: 6.4 | CVSSv2: NA | VMScore: 740 | EPSS: 0.00038 | KEV: Not Included
Published: 13/03/2025 Updated: 13/03/2025

Vulnerability Summary

Stored XSS in CC-IMG-Shortcode WordPress Plugin via Shortcode Attributes

The CC-IMG-Shortcode plugin for WordPress version 1.1.0 and earlier has a Stored Cross-Site Scripting vulnerability through its 'img' shortcode. The issue stems from weak input sanitization and output escaping of user-supplied attributes. Attackers with contributor-level or higher permissions can inject malicious web scripts into pages. When a user views an infected page, these injected scripts will automatically execute, potentially compromising the website's security and user experience.

Vulnerable Product Search on Vulmon Subscribe to Product

clearcodehq cc-img-shortcode