Stored Cross-Site Scripting in WP Easy Toggles Plugin by WordPress
CVE-2025-10190

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
11 October 2025

What is CVE-2025-10190?

The WP Easy Toggles plugin allows attackers with contributor-level access to exploit vulnerabilities in the plugin's handling of the 'toggles' shortcode. Due to inadequate input validation and output escaping on user-supplied attributes, authenticated users can inject malicious scripts. These scripts are executed in the browsers of users accessing affected pages, potentially compromising their security. This flaw highlights the importance of robust input sanitization practices in plugin development to safeguard against web-based attacks.

Affected Version(s)

WP Easy Toggles * <= 1.9.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Djaidja Moundjid
.
CVE-2025-10190 : Stored Cross-Site Scripting in WP Easy Toggles Plugin by WordPress