Reflected Cross-Site Scripting in Hubbub Lite Plugin for WordPress
CVE-2025-12471
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 6 November 2025
What is CVE-2025-12471?
The Hubbub Lite plugin, used for social sharing in WordPress, suffers from a vulnerability that allows for Reflected Cross-Site Scripting (XSS). This issue arises due to inadequate input sanitization and output escaping in the 'dpsp_list_attention_search' parameter. Unauthenticated attackers can exploit this flaw to inject arbitrary web scripts into pages, potentially misleading users into executing these scripts by clicking on crafted links. All versions up to and including 1.36.0 are affected, which poses a significant risk to website security.
Affected Version(s)
Hubbub Lite – Fast, free social sharing and follow buttons * <= 1.36.0