Cross-Site Scripting Vulnerability in AyeCode Ltd Ketchup Shortcodes
CVE-2025-24673
6.5MEDIUM
What is CVE-2025-24673?
The Ketchup Shortcodes plugin by AyeCode Ltd has a vulnerable implementation allowing for stored Cross-Site Scripting (XSS). Through improper neutralization of script-related HTML tags, attackers can inject malicious scripts that are executed when users access affected pages. This vulnerability poses significant web security risks, particularly for WordPress sites utilizing this plugin version from n/a to 0.1.2, enabling the possibility of data theft and unauthorized actions within a user's session.
Affected Version(s)
Ketchup Shortcodes <= 0.1.2