Cross Site Scripting Vulnerability in Elizaibots Plugin by WordPress
CVE-2025-15659
6.5MEDIUM
What is CVE-2025-15659?
The Elizaibots plugin versions up to 1.0.2 are susceptible to a Cross Site Scripting (XSS) vulnerability. This issue arises from improper handling of user input, allowing attackers to inject malicious scripts. If exploited, these scripts could be executed in the context of users' sessions, potentially compromising user data and leading to unauthorized actions on the affected WordPress sites. Website administrators should take immediate action to update their plugins and mitigate the risks associated with this vulnerability.
Affected Version(s)
Elizaibots <= 1.0.2