What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scribit Shortcodes Finder allows Reflected XSS.This issue affects Shortcodes Finder: from n/a through 1.5.5.
Explanation of Vulnerability in Simple Terms
02Summary
Scribit Shortcodes Finder versions up to 1.5.5 contain a cross-site scripting (XSS) vulnerability. An attacker can inject malicious scripts that execute in a victim's browser when they visit a crafted page. The vulnerability affects the scope beyond the vulnerable component, potentially compromising user sessions and data. A patch version has not been publicly identified.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in a victim's browser to steal session data or perform actions on their behalf.
Potential impact on your site
04Site Impact
Users visiting affected pages may have their sessions hijacked or credentials stolen; site reputation and user trust at risk.
Conditions required to exploit
05Prerequisites
Victim must visit a page containing the attacker's malicious payload; no authentication required.
Key dates
06Disclosure timeline
February 1, 2024
CVE published
April 28, 2026
Record updated