Cross-site Scripting Vulnerability in Memberlite Shortcodes Plugin by WordPress
CVE-2025-48087
6.5MEDIUM
What is CVE-2025-48087?
The Memberlite Shortcodes plugin for WordPress has a vulnerability that allows for improper neutralization of input during web page generation. This stored Cross-site Scripting (XSS) flaw can be exploited by malicious users to inject arbitrary web scripts into pages viewed by other users. Affected users of the plugin from versions n/a through 1.4.1 should take immediate action to mitigate potential attacks and protect sensitive data.
Affected Version(s)
Memberlite Shortcodes <= 1.4.1