Stored Cross-Site Scripting vulnerability in Responsive Progress Bar plugin for WordPress
CVE-2025-11883
6.4MEDIUM
What is CVE-2025-11883?
The Responsive Progress Bar plugin for WordPress has a vulnerability that allows authenticated users, having contributor-level access or higher, to exploit insufficient input sanitization and output escaping on user-supplied attributes. This flaw in the plugin's rprogress shortcode permits attackers to inject malicious web scripts into pages. These scripts may execute every time an unsuspecting user accesses the compromised page, posing significant security risks.
Affected Version(s)
Responsive Progress Bar * <= 1.0