Stored Cross-Site Scripting in Magical Posts Display Plugin for WordPress
CVE-2025-12965

6.4MEDIUM

What is CVE-2025-12965?

The Magical Posts Display plugin for WordPress has a vulnerability that allows authenticated attackers with Author-level access to exploit the 'mpac_title_tag' parameter in the Magical Posts Accordion widget. Due to inadequate input sanitization and output escaping of user-supplied HTML tag names, adversaries can inject malicious scripts into pages. This results in the execution of arbitrary web scripts whenever a user accesses an affected page, compromising the integrity of the website and potentially leading to further security breaches.

Affected Version(s)

Magical Posts Display – Elementor Advanced Posts widgets * <= 1.2.54

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abu Hurayra
.
CVE-2025-12965 : Stored Cross-Site Scripting in Magical Posts Display Plugin for WordPress