Stored Cross-Site Scripting Vulnerability in XX2WP Integration Tools Plugin for WordPress
CVE-2025-11857
6.4MEDIUM
What is CVE-2025-11857?
The XX2WP Integration Tools plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of the 'post_id' parameter. This vulnerability affects all versions up to and including 1.9.9, allowing authenticated attackers with contributor-level access and higher to embed malicious scripts. When users load affected pages, these scripts can execute, potentially compromising user data and site integrity. Proper input and output validation measures should be implemented to mitigate such risks.
Affected Version(s)
XX2WP Integration Tools * <= 1.9.9