Stored Cross-Site Scripting Vulnerability in RandomQuotr Plugin for WordPress
CVE-2025-12632
5.5MEDIUM
What is CVE-2025-12632?
The RandomQuotr plugin for WordPress exhibits a vulnerability that allows for Stored Cross-Site Scripting due to inadequate input sanitization and output escaping in its admin settings. This vulnerability can be exploited by authenticated users with administrator-level permissions to inject arbitrary scripts into pages that will execute whenever a user accesses those pages. It specifically impacts multi-site installations or those where the unfiltered_html option has been disabled, posing a risk to website security.
Affected Version(s)
RandomQuotr * <= 1.0.4