Stored Cross-Site Scripting Vulnerability in Geopost Plugin for WordPress
CVE-2025-12754
6.4MEDIUM
What is CVE-2025-12754?
The Geopost plugin for WordPress is susceptible to Stored Cross-Site Scripting due to improper input sanitization and output escaping of the 'height' parameter in the 'geopost' shortcode. This vulnerability allows attackers with contributor-level access and above to inject malicious scripts into pages, leading to potential execution of harmful web scripts when users access affected pages.
Affected Version(s)
Geopost * <= 1.2