Stored Cross-Site Scripting in Puzzles Theme for WordPress
CVE-2025-0837
5.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 13 February 2025
What is CVE-2025-0837?
The Puzzles theme for WordPress contains a vulnerability that allows authenticated users with contributor-level permissions or higher to exploit stored cross-site scripting (XSS). This occurs due to inadequate sanitization of user-supplied attributes in shortcodes. Malicious actors can inject arbitrary scripts into pages, causing these scripts to execute whenever a user accesses an affected page. The lack of proper output escaping further exacerbates the risk, making it imperative for site administrators to update to versions beyond 4.2.4.
Affected Version(s)
Puzzles | WP Magazine / Review with Store WordPress Theme + RTL * <= 4.2.4