Stored Cross-Site Scripting Vulnerability in Trail Manager Plugin for WordPress
CVE-2025-13682
What is CVE-2025-13682?
The Trail Manager plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability, which arises from inadequate input sanitization and output encoding practices. Authenticated attackers with administrator privileges can exploit this weakness to inject malicious scripts into pages that execute whenever other users access those pages. This issue particularly impacts multi-site installations and those where unfiltered_html functionality is disabled, posing significant risks to end users and the integrity of the site.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Trail Manager * <= 1.0.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved