Cross-Site Scripting Vulnerability in Post Connector by Barry Kooij
CVE-2025-52741

9CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
22 October 2025

What is CVE-2025-52741?

The Post Connector plugin by Barry Kooij is susceptible to a Cross-Site Scripting (XSS) vulnerability due to improper neutralization of input during web page generation. This flaw allows attackers to execute malicious scripts in the context of web users, potentially compromising sensitive information or manipulating site behavior. The issue is present in versions up to and including 1.0.11, highlighting the importance for users to update and secure their installations to mitigate risk.

Affected Version(s)

Post Connector <= n/a

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Xuan Chien (Patchstack Alliance)
.