Stored Cross-Site Scripting in WP Airbnb Review Slider Plugin for WordPress
CVE-2025-12520

4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 November 2025

What is CVE-2025-12520?

The WP Airbnb Review Slider plugin for WordPress is exposed to Stored Cross-Site Scripting vulnerabilities due to inadequate URL validation. This flaw permits authenticated users with administrator-level permissions to inject malicious HTML into the admin settings, leading to the potential execution of arbitrary web scripts on pages accessed by other users. Notably, this issue affects multi-site installations and those where unfiltered_html is disabled, raising concerns over unauthorized script execution and data exposure.

Affected Version(s)

WP Airbnb Review Slider * <= 4.2

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CyberResearchHub.com
.
CVE-2025-12520 : Stored Cross-Site Scripting in WP Airbnb Review Slider Plugin for WordPress