Stored Cross-Site Scripting Vulnerability in WP Photo Effects Plugin by WordPress
CVE-2025-10192

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2025

What is CVE-2025-10192?

The WP Photo Effects plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) attacks due to inadequate sanitization and escaping of user-supplied data. This vulnerability exists in the 'wppe_effect' shortcode, impacting all versions up to and including 1.2.4. Authenticated attackers with contributor-level access or higher can exploit this vulnerability to inject malicious scripts into web pages, which will execute for users who access those altered pages. This poses significant security risks for WordPress sites utilizing this plugin, emphasizing the need for prompt updates and vigilant security practices.

Affected Version(s)

WP Photo Effects * <= 1.2.4

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Djaidja Moundjid
.
CVE-2025-10192 : Stored Cross-Site Scripting Vulnerability in WP Photo Effects Plugin by WordPress