Stored Cross-site Scripting in Nurelm Get Posts Plugin
CVE-2025-27349
What is CVE-2025-27349?
The Nurelm Get Posts plugin for WordPress contains a vulnerability that allows for stored cross-site scripting (XSS) attacks. This occurs due to improper handling of input during web page generation, enabling attackers to inject malicious scripts. Consequently, when users interact with the affected plugin, these scripts may execute in their browsers, potentially compromising their data and overall site security. It is imperative for users of the Nurelm Get Posts plugin to implement necessary updates and enhancements to protect their websites from exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Get Posts <= 0.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved