Reflected Cross-Site Scripting in WP-SOS-Donate Donation Sidebar Plugin for WordPress
CVE-2025-13625
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 December 2025
What is CVE-2025-13625?
The WP-SOS-Donate Donation Sidebar Plugin for WordPress suffers from a reflected cross-site scripting vulnerability due to inadequate input sanitization and output escaping in the handling of the $_SERVER['PHP_SELF'] parameter. This flaw affects all versions up to and including 0.9.2. An attacker can exploit this vulnerability by crafting a link that tricks victims into clicking it, allowing for the injection of arbitrary scripts into web pages that will execute within the user's browser.
Affected Version(s)
WP-SOS-Donate Donation Sidebar Plugin * <= 0.9.2