Cross-site Scripting Vulnerability in WP Super Edit by Ahmad Awais
CVE-2025-49948
7.1HIGH
What is CVE-2025-49948?
A vulnerability exists in WP Super Edit, created by Ahmad Awais, due to improper neutralization of user input during web page generation. This flaw allows attackers to exploit reflected cross-site scripting (XSS) vulnerabilities, potentially compromising the security of users interacting with affected versions of the plugin. Users should take immediate precautions to secure their sites, especially if using versions up to and including 2.5.4.
Affected Version(s)
WP Super Edit 0 <= 2.5.4