Stored Cross-Site Scripting Vulnerability in Sermon Manager Plugin for WordPress
CVE-2025-12368
6.4MEDIUM
What is CVE-2025-12368?
The Sermon Manager plugin for WordPress contains a vulnerability that allows authenticated attackers with Contributor-level access or higher to exploit the sermon-views shortcode. This is due to a failure in properly sanitizing input and escaping output on user-supplied attributes. As a result, attackers can inject malicious scripts, which execute in the browsers of users accessing the compromised pages, potentially leading to further attacks or data breaches.
Affected Version(s)
Sermon Manager * <= 2.30.0