Stored Cross-Site Scripting in Puzzles Theme for WordPress
CVE-2025-0837

5.4MEDIUM

What is CVE-2025-0837?

The Puzzles theme for WordPress contains a vulnerability that allows authenticated users with contributor-level permissions or higher to exploit stored cross-site scripting (XSS). This occurs due to inadequate sanitization of user-supplied attributes in shortcodes. Malicious actors can inject arbitrary scripts into pages, causing these scripts to execute whenever a user accesses an affected page. The lack of proper output escaping further exacerbates the risk, making it imperative for site administrators to update to versions beyond 4.2.4.

Affected Version(s)

Puzzles | WP Magazine / Review with Store WordPress Theme + RTL * <= 4.2.4

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.