Stored Cross-Site Scripting Vulnerability in Nearby Now Reviews Plugin for WordPress
CVE-2025-13853
6.4MEDIUM
What is CVE-2025-13853?
The Nearby Now Reviews plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) attacks through the 'data_tech' parameter of the nn-tech shortcode. This vulnerability arises from inadequate input sanitization and output escaping in all versions up to and including 5.2. Authenticated attackers with Contributor-level access can exploit this flaw to inject arbitrary web scripts, which are then executed whenever users access the compromised pages.
Affected Version(s)
Nearby Now Reviews 0 <= 5.2