Stored Cross-Site Scripting Vulnerability in SNORDIAN's H5PxAPIkatchu Plugin for WordPress
CVE-2025-12904
7.2HIGH
What is CVE-2025-12904?
The H5PxAPIkatchu plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit the 'insert_data' AJAX endpoint. This flaw arises from inadequate input sanitization and output escaping, enabling the injection of arbitrary web scripts into pages. When a user accesses an affected page, the injected scripts execute in their browser context, potentially leading to severe security implications.
Affected Version(s)
SNORDIAN's H5PxAPIkatchu * <= 0.4.17