Stored Cross-Site Scripting in WP Easy Toggles Plugin by WordPress
CVE-2025-10190
What is CVE-2025-10190?
The WP Easy Toggles plugin allows attackers with contributor-level access to exploit vulnerabilities in the plugin's handling of the 'toggles' shortcode. Due to inadequate input validation and output escaping on user-supplied attributes, authenticated users can inject malicious scripts. These scripts are executed in the browsers of users accessing affected pages, potentially compromising their security. This flaw highlights the importance of robust input sanitization practices in plugin development to safeguard against web-based attacks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WP Easy Toggles * <= 1.9.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved