Stored Cross-Site Scripting Vulnerability in XX2WP Integration Tools Plugin for WordPress
CVE-2025-11857
What is CVE-2025-11857?
The XX2WP Integration Tools plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) due to inadequate sanitization of the 'post_id' parameter. This vulnerability affects all versions up to and including 1.9.9, allowing authenticated attackers with contributor-level access and higher to embed malicious scripts. When users load affected pages, these scripts can execute, potentially compromising user data and site integrity. Proper input and output validation measures should be implemented to mitigate such risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
XX2WP Integration Tools * <= 1.9.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved