Reflected XSS Vulnerability in Sayocode SC Simple Zazzle Plugin
CVE-2025-23733
7.1HIGH
What is CVE-2025-23733?
A reflected Cross-site Scripting vulnerability exists in the Sayocode SC Simple Zazzle plugin, allowing attackers to inject malicious scripts into web pages. This vulnerability impacts all versions of the plugin up to 1.1.6, enabling unauthorized users to execute scripts in the context of a victim’s browser, potentially leading to data theft, session hijacking, or further exploitation of the website.
Affected Version(s)
SC Simple Zazzle <= 1.1.6