Stored Cross-Site Scripting in WishSuite Plugin for WordPress
CVE-2025-13838
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 21 December 2025
What is CVE-2025-13838?
The WishSuite plugin for WordPress is vulnerable to a Stored Cross-Site Scripting attack via the 'button_text' parameter within the 'wishsuite_button' shortcode. This vulnerability arises due to inadequate input sanitization and output escaping, allowing authenticated users with Contributor-level access and above to inject arbitrary scripts. As a result, when affected pages are accessed, these scripts can be executed by any user, potentially compromising website integrity and user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WishSuite β Wishlist for WooCommerce * <= 1.5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved