Stored Cross-Site Scripting Vulnerability in WP Extended Plugin for WordPress
CVE-2025-4963
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 28 May 2025
What is CVE-2025-4963?
The WP Extended plugin for WordPress suffers from a stored cross-site scripting vulnerability that arises from inadequate input sanitization and output escaping mechanisms. This vulnerability specifically affects versions up to and including 3.0.15. Authenticated attackers with Author-level permissions or higher can exploit this flaw by uploading malicious SVG files. When these files are accessed, they can execute arbitrary web scripts within the context of the victim’s session, leading to potential data theft or other malicious actions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
The Ultimate WordPress Toolkit – WP Extended * <= 3.0.15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved