Stored Cross-Site Scripting in My AskAI Plugin by WordPress
CVE-2025-10179
6.4MEDIUM
What is CVE-2025-10179?
The My AskAI plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability. This issue arises from inadequate input sanitization and output escaping on user-supplied attributes, particularly through the 'myaskai' shortcode. As a result, attackers with contributor-level access can inject arbitrary web scripts into pages. These scripts execute whenever users visit the affected pages, potentially leading to further exploitation or data compromise.
Affected Version(s)
My AskAI * <= 1.0.0