Stored Cross-Site Scripting Vulnerability in Z Companion Plugin for WordPress
CVE-2025-2575
What is CVE-2025-2575?
The Z Companion plugin for WordPress contains a vulnerability that allows authenticated users with author-level access and above to exploit stored cross-site scripting (XSS) through SVG file uploads. This vulnerability arises from the lack of proper input sanitization and output escaping, enabling attackers to inject malicious web scripts that will execute whenever a user accesses the affected SVG file. The vulnerability specifically requires the Royal Shop theme to be installed to facilitate the exploit, raising concerns about the overall security of WordPress sites utilizing this plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Z Companion * <= 1.1.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved