Stored Cross-Site Scripting Vulnerability in Extra Post Images Plugin for WordPress
CVE-2025-13856
6.4MEDIUM
What is CVE-2025-13856?
The Extra Post Images plugin for WordPress has a vulnerability in the handling of the 'id' parameter within the extra-images shortcode. This lack of proper input sanitization and output escaping allows authenticated attackers, with Contributor-level access, to inject malicious scripts. These scripts can execute whenever a user accesses a compromised page, posing significant risks to website integrity and user safety.
Affected Version(s)
Extra Post Images * <= 1.0