Stored Cross-Site Scripting Vulnerability in XX2WP Integration Tools Plugin for WordPress
CVE-2025-11857

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 October 2025

What is CVE-2025-11857?

The XX2WP Integration Tools plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of the 'post_id' parameter. This vulnerability affects all versions up to and including 1.9.9, allowing authenticated attackers with contributor-level access and higher to embed malicious scripts. When users load affected pages, these scripts can execute, potentially compromising user data and site integrity. Proper input and output validation measures should be implemented to mitigate such risks.

Affected Version(s)

XX2WP Integration Tools * <= 1.9.9

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Muhammad Yudha - DJ
.
CVE-2025-11857 : Stored Cross-Site Scripting Vulnerability in XX2WP Integration Tools Plugin for WordPress