Stored Cross-Site Scripting Vulnerability in Minimal Share Buttons for WordPress
CVE-2025-5259
6.4MEDIUM
What is CVE-2025-5259?
The Minimal Share Buttons plugin for WordPress has a vulnerability that allows authenticated attackers with Contributor-level access and above to exploit the âalignâ parameter. Due to insufficient input sanitization and output escaping, attackers can inject malicious web scripts into pages. These scripts execute whenever a user accesses an affected page, potentially compromising user data and site integrity.
Affected Version(s)
Minimal Share Buttons * <= 1.7.3