Stored Cross-Site Scripting in Magical Posts Display Plugin for WordPress
CVE-2025-12965
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 December 2025
What is CVE-2025-12965?
The Magical Posts Display plugin for WordPress has a vulnerability that allows authenticated attackers with Author-level access to exploit the 'mpac_title_tag' parameter in the Magical Posts Accordion widget. Due to inadequate input sanitization and output escaping of user-supplied HTML tag names, adversaries can inject malicious scripts into pages. This results in the execution of arbitrary web scripts whenever a user accesses an affected page, compromising the integrity of the website and potentially leading to further security breaches.
Affected Version(s)
Magical Posts Display β Elementor Advanced Posts widgets * <= 1.2.54