Stored XSS Vulnerability in VK All in One Expansion Unit Plugin for WordPress
CVE-2025-11267
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 November 2025
What is CVE-2025-11267?
The VK All in One Expansion Unit plugin for WordPress is prone to a Stored Cross-Site Scripting vulnerability due to insufficient input validation and output escaping related to the '_veu_custom_css' parameter. Authenticated attackers with Contributor-level access and higher can exploit this flaw by injecting malicious scripts into web pages that will be executed whenever a user accesses those pages. This vulnerability highlights the importance of robust input handling and security measures in web applications.
Affected Version(s)
VK All in One Expansion Unit * <= 9.112.1