Stored XSS Vulnerability in Related Post Shortcode by Enguerran Weiss
CVE-2025-22276

5.9MEDIUM

Key Information:

Vendor
WordPress
Vendor
CVE Published:
21 January 2025

Summary

A stored Cross-site Scripting (XSS) vulnerability has been identified in the Related Post Shortcode plugin developed by Enguerran Weiss. This security issue allows attackers to inject malicious scripts that can be executed in the context of users visiting affected web pages. The vulnerability affects the plugin from versions n/a through 1.2, making it essential for users to update or implement security measures to safeguard their sites.

Affected Version(s)

Related Post Shortcode <= 1.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pham Ngoc Duy (Patchstack Alliance)
.