Stored Cross-Site Scripting Vulnerability in Name Directory Plugin for WordPress
CVE-2025-15283
7.2HIGH
What is CVE-2025-15283?
The Name Directory plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) through the 'name_directory_name' and 'name_directory_description' parameters. This vulnerability arises from failure to adequately sanitize user input and escape output, enabling unauthenticated attackers to embed arbitrary web scripts. These scripts execute on the browsers of users accessing compromised pages, potentially leading to session hijacking, data theft, or other malicious activities.
Affected Version(s)
Name Directory 0 <= 1.30.3