Stored Cross-Site Scripting Vulnerability in WordPress Plugins
CVE-2025-2537
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 3 July 2025
What is CVE-2025-2537?
Multiple WordPress plugins are susceptible to Stored Cross-Site Scripting due to failures in adequate input sanitization and output escaping on user-provided attributes. The vulnerability arises from the bundled ThickBox JavaScript library, version 3.1. Authenticated attackers with contributor-level access and above can exploit this weakness to inject arbitrary scripts that execute on users’ browsers when they visit affected pages.
Affected Version(s)
Auto Thickbox * <= 3.5
Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery * <= 3.59.11
YouTube Embed, Playlist and Popup by WpDevArt * <= 2.6.7