Cross-Site Scripting Vulnerability in Biscia7 Hide Text Shortcode Plugin
CVE-2025-49051

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 August 2025

What is CVE-2025-49051?

The Biscia7 Hide Text Shortcode plugin is affected by a Cross-Site Scripting vulnerability that arises from improper input validation during web page generation. This flaw allows attackers to store malicious scripts, which could be executed in the context of users accessing the affected site. As a result, sensitive information could be compromised. Users and web administrators should take immediate steps to assess their installations and implement recommended security measures to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Hide Text Shortcode <= 1.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

theviper17 (Patchstack Alliance)
.