Stored Cross-Site Scripting in WishSuite Plugin for WordPress
CVE-2025-13838
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 December 2025
What is CVE-2025-13838?
The WishSuite plugin for WordPress is vulnerable to a Stored Cross-Site Scripting attack via the 'button_text' parameter within the 'wishsuite_button' shortcode. This vulnerability arises due to inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level access and above to inject arbitrary scripts. As a result, when affected pages are accessed, these scripts can be executed by any user, potentially compromising website integrity and user data.
Affected Version(s)
WishSuite β Wishlist for WooCommerce * <= 1.5.1