Stored Cross-Site Scripting Vulnerability in AI Feeds Plugin for WordPress
CVE-2025-14030
6.4MEDIUM
What is CVE-2025-14030?
The AI Feeds plugin for WordPress suffers from a vulnerability that allows authenticated users with Contributor-level access or higher to execute arbitrary web scripts on affected pages. This vulnerability arises from inadequate input sanitization and output escaping within the 'aife_post_meta' shortcode. As a result, malicious scripts could be injected into page content, posing significant risks to user data and site integrity when users access those compromised pages.
Affected Version(s)
AI Feeds * <= 1.0.22