Cross-site Scripting Vulnerability in WP Codeus Advanced Sermons Plugin
CVE-2025-49863
6.5MEDIUM
What is CVE-2025-49863?
The WP Codeus Advanced Sermons plugin is susceptible to an improper neutralization of input during web page generation, leading to a Stored XSS vulnerability. This issue allows attackers to inject malicious scripts into web pages viewed by users, potentially compromising sensitive data and overall web security. Affected versions range from n/a through 3.6, making it crucial for users to assess their installations and apply necessary updates to mitigate the risk.
Affected Version(s)
Advanced Sermons <= 3.6