Stored Cross-Site Scripting Vulnerability in dbview Plugin for WordPress
CVE-2025-10182
6.4MEDIUM
What is CVE-2025-10182?
The dbview plugin for WordPress is vulnerable to a Stored Cross-Site Scripting (XSS) flaw through the 'dbview' shortcode. The vulnerability arises from inadequate input sanitization and output escaping of user-supplied attributes. This issue allows authenticated attackers with contributor-level permissions or higher to inject and execute arbitrary web scripts on pages accessed by users, potentially leading to theft of sensitive information or session hijacking.
Affected Version(s)
dbview * <= 0.5.5